Skip to content

chore: fix vuln: override autolinker ^4.0.0#785

Merged
ramonpetgrave64 merged 3 commits intoslsa-framework:mainfrom
ramonpetgrave64:ramonpetgrave64-fix-markdown-toc-vuln
Aug 13, 2024
Merged

chore: fix vuln: override autolinker ^4.0.0#785
ramonpetgrave64 merged 3 commits intoslsa-framework:mainfrom
ramonpetgrave64:ramonpetgrave64-fix-markdown-toc-vuln

Conversation

@ramonpetgrave64
Copy link
Copy Markdown
Contributor

@ramonpetgrave64 ramonpetgrave64 commented Jun 28, 2024

fixes https://github.com/slsa-framework/slsa-verifier/security/code-scanning/11

markdown-toc's latest v1.2.0 is still vulnerable via a transitive dependency, but hasn't received updates in a long time.

This PR overrides one of the other transitive dependencies to a non-vulnerable version.

more info here jonschlinkert/markdown-toc#156 (comment)

Testing process

  • Manually invoked make markdown-toc and it did succeed, while also adding a missing header in the README.
  • Made a few typos in the headers and markdown-toc did fix them.
  • Cloned markdown-toc, added the override, and its unit tests passed

Signed-off-by: Ramon Petgrave <ramon.petgrave64@gmail.com>
@ramonpetgrave64 ramonpetgrave64 changed the title deps: fix vuln: override autolinker >= 4.0.0 ^4.0.0 chore: fix vuln: override autolinker >= 4.0.0 ^4.0.0 Jun 28, 2024
@ramonpetgrave64 ramonpetgrave64 marked this pull request as ready for review June 28, 2024 21:13
@ramonpetgrave64
Copy link
Copy Markdown
Contributor Author

@ramonpetgrave64 ramonpetgrave64 requested a review from ianlewis June 28, 2024 21:14
Signed-off-by: Ramon Petgrave <32398091+ramonpetgrave64@users.noreply.github.com>
@ramonpetgrave64 ramonpetgrave64 changed the title chore: fix vuln: override autolinker >= 4.0.0 ^4.0.0 chore: fix vuln: override autolinker ^4.0.0 Jul 26, 2024
@loosebazooka
Copy link
Copy Markdown
Contributor

loosebazooka commented Aug 13, 2024

sorry I was logged in as distroless-bot

@ramonpetgrave64 ramonpetgrave64 requested a review from a team August 13, 2024 18:53
@ramonpetgrave64 ramonpetgrave64 enabled auto-merge (squash) August 13, 2024 18:54
@ramonpetgrave64 ramonpetgrave64 merged commit 3f37511 into slsa-framework:main Aug 13, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants