You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
-
Summary
8 moderate npm vulnerabilities persist in documentation dependencies (same as Jan 22). Mermaid v11.12.2 continues to revert despite previous fixes.
Key Findings
Security⚠️
Repository Health ✅
Could Not Verify (Go not in environment)
Actions Taken
Root Cause Analysis
Why vulnerabilities keep recurring:
docs/package.jsonspecifies"mermaid": "^11.12.2"(caret allows updates)npm cireinstalls from package.json, reverting to 11.12.2Recommendations
Immediate Fix:
docs/package.json:"mermaid": "~10.9.5"(tilde prevents major/minor updates)npm installto update lock fileLong-term:
Commands Used
Package.json Mermaid Config
{ "dependencies": { "`@astrojs/starlight`": "^0.37.3", "astro": "^5.16.9", "astro-mermaid": "^1.1.0", "mermaid": "^11.12.2", "sharp": "^0.34.5", "starlight-links-validator": "^0.19.2" } }Issue: Caret (^) allows npm to install latest 11.x version, causing reverts.
Beta Was this translation helpful? Give feedback.
All reactions