fix(deps): bump markdown-it to ^14.3.2 to address GHSA-253c-mchw-3w2r - #250
Merged
Merged
Conversation
markdown-it <14.3.1 with linkify enabled has two quadratic paths that let a few hundred KB of markdown block the event loop for tens of seconds. MacroConverter enables linkify, so markdown → storage is exposed. The advisory also fails the release workflow's npm audit gate, which blocked the release of #249.
github-actions Bot
pushed a commit
that referenced
this pull request
Sep 30, 2026
## [2.25.4](v2.25.3...v2.25.4) (2026-09-30) ### Bug Fixes * **deps:** bump markdown-it to ^14.3.2 to address GHSA-253c-mchw-3w2r ([#250](#250)) ([1df64d5](1df64d5)), closes [#249](#249) * **storage-walker:** keep code blocks inside blockquotes and callouts byte-exact ([#249](#249)) ([dadfc93](dadfc93)), closes [#244](#244)
|
🎉 This PR is included in version 2.25.4 🎉 The release is available on: Your semantic-release bot 📦🚀 |
This was referenced Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Bumps
markdown-itfrom^14.1.0(resolved 14.2.0) to^14.3.2to address GHSA-253c-mchw-3w2r (moderate).With
linkify: true,markdown-it<14.3.1 has two quadratic paths, so a few hundred KB of markdown can block the event loop for tens of seconds.MacroConverter.setupConfluenceMarkdownExtensions()enableslinkify, so the markdown → storage path is affected.The advisory was published after #249's PR checks ran, so the
securityjob (npm audit --audit-level moderate --omit=dev) failed on the post-mergemainrun. That skippedpublishandupdate-homebrew, and #249 has not been released yet. Merging thisfix(deps)commit clears the gate and releases #249 together with this fix.The lockfile diff only touches
markdown-itand its direct dependency ranges (entities^4.5.0,linkify-it^5.0.2).Type of Change
Testing
npm audit --audit-level moderate --omit=dev: found 0 vulnerabilities.npx jest: 1299 passed.npx eslint lib tests: clean.Checklist