Skip to content

fix: Upgrade rehype packages to fix mdast-util-to-hast vulnerability#11616

Merged
anthonyshew merged 2 commits intomainfrom
anthonyshew/turbo-5159-mdast-util
Feb 1, 2026
Merged

fix: Upgrade rehype packages to fix mdast-util-to-hast vulnerability#11616
anthonyshew merged 2 commits intomainfrom
anthonyshew/turbo-5159-mdast-util

Conversation

@anthonyshew
Copy link
Contributor

Summary

  • Upgrades remark-rehype from 11.1.1 to 11.1.2 in docs/link-checker
  • Forces mdast-util-to-hast resolution from 13.2.0 to 13.2.1 (patched version)

Addresses TURBO-5159: mdast-util-to-hast unsanitized class attribute vulnerability (CVE affected versions >=13.0.0 <13.2.1).

Test

Link checker validated successfully after upgrade.

@anthonyshew anthonyshew requested a review from a team as a code owner February 1, 2026 04:18
@anthonyshew anthonyshew requested review from tknickman and removed request for a team February 1, 2026 04:18
@turbo-orchestrator turbo-orchestrator bot added the area: site Issues and improvements related to Turborepo's documentation website label Feb 1, 2026
@vercel
Copy link
Contributor

vercel bot commented Feb 1, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
examples-basic-web Ready Ready Preview, Comment, Open in v0 Feb 1, 2026 9:22pm
examples-designsystem-docs Ready Ready Preview, Comment, Open in v0 Feb 1, 2026 9:22pm
examples-gatsby-web Ready Ready Preview, Comment, Open in v0 Feb 1, 2026 9:22pm
examples-kitchensink-blog Ready Ready Preview, Comment, Open in v0 Feb 1, 2026 9:22pm
examples-nonmonorepo Ready Ready Preview, Comment, Open in v0 Feb 1, 2026 9:22pm
examples-svelte-web Ready Ready Preview, Comment, Open in v0 Feb 1, 2026 9:22pm
examples-tailwind-web Ready Ready Preview, Comment, Open in v0 Feb 1, 2026 9:22pm
examples-vite-web Ready Ready Preview, Comment, Open in v0 Feb 1, 2026 9:22pm
turbo-site Ready Ready Preview, Comment, Open in v0 Feb 1, 2026 9:22pm
turborepo-test-coverage Ready Ready Preview, Comment, Open in v0 Feb 1, 2026 9:22pm

@vercel vercel bot temporarily deployed to Preview – turborepo-test-coverage February 1, 2026 04:18 Inactive
@anthonyshew anthonyshew merged commit c79e54e into main Feb 1, 2026
46 of 47 checks passed
@anthonyshew anthonyshew deleted the anthonyshew/turbo-5159-mdast-util branch February 1, 2026 21:23
anthonyshew pushed a commit that referenced this pull request Feb 1, 2026
## Canary Release

Versioned docs: https://v2-8-2-canary-3.turborepo.dev

### Included Changes

- 469f9dd - fix: Upgrade ts-jest to 29.4.6 to fix brace-expansion ReDoS
vulnerabilities (#11623) (#11623)
- af6aef8 - fix: Upgrade inquirer to 8.2.7 to fix tmp vulnerability
(#11622) (#11622)
- 73e1a65 - fix: Consolidate canary releases into release workflow for
npm trusted publishing (#11624) (#11624)
- e192b8e - fix: Upgrade diff to fix DoS vulnerabilities (#11621)
(#11621)
- c79e54e - fix: Upgrade rehype packages to fix mdast-util-to-hast
vulnerability (#11616) (#11616)
- aceb210 - fix: Pass secrets explicitly in canary workflow (#11620)
(#11620)
- d6ca8cd - fix: Add explicit secrets declarations to release
workflow_call trigger (#11619) (#11619)
- a0c22ca - ci: Automated canary release pipeline (#11618) (#11618)

---
Release PR for turborepo v2.8.2-canary.3

Co-authored-by: Turbobot <turbobot@vercel.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: site Issues and improvements related to Turborepo's documentation website

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant