Skip to content

chore(deps): upgrade mdast-util-to-hast to >=13.2.1#395

Merged
mherod merged 2 commits intomainfrom
chore/upgrade-mdast-util-to-hast
Dec 2, 2025
Merged

chore(deps): upgrade mdast-util-to-hast to >=13.2.1#395
mherod merged 2 commits intomainfrom
chore/upgrade-mdast-util-to-hast

Conversation

@mherod
Copy link
Owner

@mherod mherod commented Dec 2, 2025

Upgrades mdast-util-to-hast to version 13.2.1 or later via pnpm overrides to address security vulnerability.

This change adds mdast-util-to-hast to the pnpm overrides section, ensuring that version 13.2.1 or later is used even as a transitive dependency (likely from VitePress or other documentation tools).

All tests and validation checks pass successfully.

@mherod mherod enabled auto-merge (squash) December 2, 2025 21:48
@claude
Copy link

claude bot commented Dec 2, 2025

PR Review: Security Dependency Upgrade

Overview

This PR adds a pnpm override for mdast-util-to-hast to address a security vulnerability. The implementation is complete and correct.

Findings

✅ All Issues Resolved

  • Lockfile properly updated - The pnpm-lock.yaml includes the override and shows version 13.2.1 is now being used throughout the dependency tree

🔵 Suggestions

  • Consider documenting which security vulnerability this addresses (CVE number or GitHub advisory link) in the PR description for future reference

👍 What's Good

  • Correct use of pnpm overrides to handle transitive dependencies
  • Lockfile properly regenerated with the override applied
  • Appropriate version constraint (>=13.2.1) for security patches
  • Clear PR description explaining the change
  • All validation checks passing

Summary

LGTM! The override is properly configured and the lockfile correctly reflects the change. Ready to merge.

Copy link

@claude claude bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving this security dependency upgrade. The pnpm override is correctly configured and the lockfile properly reflects the change to mdast-util-to-hast >=13.2.1. All validation checks pass.

@mherod mherod merged commit bebef9e into main Dec 2, 2025
14 checks passed
@mherod mherod deleted the chore/upgrade-mdast-util-to-hast branch December 2, 2025 21:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant