diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index 54d0f0a6d0..0fa188c53b 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -41,6 +41,7 @@ overrides: qs@>=6.0.0 <7.0.0: ^6.16.0 devalue@<6.0.0: ^5.9.2 ip-address@<11.0.0: ^10.5.1 + katex@>=0.11.0 <0.19.0: ^0.18.2 patchedDependencies: tsup@8.5.1: @@ -6087,10 +6088,6 @@ packages: resolution: {integrity: sha512-QrWXB+ZQSVPmIWIhtEO9H+gwHaMGYiF5ChvoJ+K9ZGHG/sVsa6yiesAD1GC/x46sET00Xlwo1u49RVVVzvcSkw==} engines: {node: '>= 10'} - commander@8.3.0: - resolution: {integrity: sha512-OkTL9umf+He2DZkUq8f8J9of7yL6RJKI24dVITBmNfZBmri9zYZQrKkuXiKhyfPSu8tUhnVBB1iKXevvnlR4Ww==} - engines: {node: '>= 12'} - commondir@1.0.1: resolution: {integrity: sha512-W9pAhw0ja1Edb5GVdIF1mjZw/ASI0AlShXM83UUGe2DVr5TdAPEA1OA8m/g8zWp9x6On7gqufY+FatDbC3MDQg==} @@ -7278,8 +7275,8 @@ packages: jws@4.0.1: resolution: {integrity: sha512-EKI/M/yqPncGUUh44xz0PxSidXFr/+r0pA70+gIYhjv+et7yxM+s29Y+VGDkovRofQem0fs7Uvf4+YmAdyRduA==} - katex@0.16.47: - resolution: {integrity: sha512-Eeo8Ys1doU1z+x8AZsPpQu+p/QcZBI5PeOo7QGQdy2x2m0MU/hYagBbGOmXwr5KVbEfVuWv9LpnQWeehogurjg==} + katex@0.18.10: + resolution: {integrity: sha512-/B6p9eY9DX7aHBfpkHdpirDTZ5QH9xTwL9y837PWuzuv41O5jFdqNQwVQEQsimY0/iVNkwBY4+4hMfhQ7d4Dbw==} hasBin: true keyv@5.6.0: @@ -8334,8 +8331,8 @@ packages: property-information@7.2.0: resolution: {integrity: sha512-IAtzIB6sUiWaJYrX9smp3V46pBGbBeLFRGdh25kg1334VcBlD8HzhPeNIWQH9zhGmo2itIe25EHt9dQP7G5hmg==} - proxy-addr@2.0.7: - resolution: {integrity: sha512-llQsMLSUDUPT44jdrU/O37qlnifitDP+ZwrmmZcoSKyLKvtZxpyV0n2/bD/N4tBAAZ/gJEdZU7KMraoK1+XYAg==} + proxy-addr@2.0.8: + resolution: {integrity: sha512-5nnx0yGyVUcY6t9RnWcARWtwT9F1D8O9rt08htPvnd49W1IgZtmLkhu9WfMzQj1cFxjHIO6connUNVW5k7AVyQ==} engines: {node: '>= 0.10'} pump@3.0.4: @@ -8692,8 +8689,8 @@ packages: resolution: {integrity: sha512-LJhUYUvItdQ0LkJTmPeaEObWXAqFyfmP85x0tch/ez9cahmhlBBLbIqDFnvBnUJGagb0JbIQrkBs1wJ+yRYpEw==} engines: {node: '>= 10.0.0', npm: '>= 3.0.0'} - source-map-js@1.2.1: - resolution: {integrity: sha512-UXWMKhLOwVKb728IUtQPXxfYU+usdybtUrK/8uGE8CQMvrhOpwvzDBwj0QhSL7MQc7vIsISBG8VQ8+IDQxpfQA==} + source-map-js@1.2.2: + resolution: {integrity: sha512-KGj/8Y43x35aZVDtt+J4mK1hoLGHULMYfSkODJNQjNDC3oW1PqPoxMwo0pLUsWM/UEGzON/NxeHywEfNXNP3Vw==} engines: {node: '>=0.10.0'} source-map@0.7.6: @@ -11286,7 +11283,7 @@ snapshots: jiti: 2.7.0 lightningcss: 1.32.0 magic-string: 0.30.21 - source-map-js: 1.2.1 + source-map-js: 1.2.2 tailwindcss: 4.3.3 '@tailwindcss/oxide-android-arm64@4.3.3': @@ -12265,8 +12262,6 @@ snapshots: commander@7.2.0: {} - commander@8.3.0: {} - commondir@1.0.1: {} compress-commons@4.1.2: @@ -12333,7 +12328,7 @@ snapshots: css-tree@3.2.1: dependencies: mdn-data: 2.27.1 - source-map-js: 1.2.1 + source-map-js: 1.2.2 csstype@3.2.3: {} @@ -12908,7 +12903,7 @@ snapshots: on-finished: 2.4.1 once: 1.4.0 parseurl: 1.3.3 - proxy-addr: 2.0.7 + proxy-addr: 2.0.8 qs: 6.16.0 range-parser: 1.3.0 router: 2.2.0 @@ -13629,9 +13624,9 @@ snapshots: jwa: 2.0.1 safe-buffer: 5.2.1 - katex@0.16.47: + katex@0.18.10: dependencies: - commander: 8.3.0 + commander: 15.0.0 keyv@5.6.0: dependencies: @@ -13886,7 +13881,7 @@ snapshots: dependencies: '@babel/parser': 7.29.7 '@babel/types': 7.29.7 - source-map-js: 1.2.1 + source-map-js: 1.2.2 make-dir@3.1.0: dependencies: @@ -14091,7 +14086,7 @@ snapshots: dayjs: 1.11.21 dompurify: 3.4.16 es-toolkit: 1.49.0 - katex: 0.16.47 + katex: 0.18.10 khroma: 2.1.0 marked: 16.4.2 roughjs: 4.6.6 @@ -14855,7 +14850,7 @@ snapshots: dependencies: nanoid: 3.3.19 picocolors: 1.1.1 - source-map-js: 1.2.1 + source-map-js: 1.2.2 postgres-array@2.0.0: {} @@ -14901,7 +14896,7 @@ snapshots: property-information@7.2.0: {} - proxy-addr@2.0.7: + proxy-addr@2.0.8: dependencies: forwarded: 0.2.0 ipaddr.js: 1.9.1 @@ -15420,7 +15415,7 @@ snapshots: smart-buffer: 4.2.0 optional: true - source-map-js@1.2.1: {} + source-map-js@1.2.2: {} source-map@0.7.6: {} diff --git a/pnpm-workspace.yaml b/pnpm-workspace.yaml index e534b0e583..4ed429cad5 100644 --- a/pnpm-workspace.yaml +++ b/pnpm-workspace.yaml @@ -536,3 +536,36 @@ overrides: # written. Transitive-only and dev-only: nothing publishable declares # undici, and both paths reach the tree through devDependencies. 'ip-address@<11.0.0': '^10.5.1' + # OSV 2026-10-06 (#21945, scheduled scan run 37407261685) — one advisory that + # names a fixed version, so this is the "take the fix" path osv-scanner.toml's + # header prescribes and NOT an exemption. + # katex GHSA-238p-pmpm-9mq7 (2.1 low) — an inherited `Object.prototype.trust` + # is read as an explicit `trust: true`, so a prototype pollution that + # already exists elsewhere lets attacker math emit links or load external + # resources. Range introduced:0.11.0 -> fixed:0.18.2, read from the OSV + # offline npm database the scanner downloads. Flagged at the single + # resolved copy 0.16.47. + # ⚠️ Unlike the dedupes above, this is a FORCED upgrade past the dependent's + # declared range. The one consumer is mermaid@11.16.1 (apps/docs declares + # mermaid ^11.16.0), which declares katex ^0.16.45, and no published + # mermaid admits the fix: 11.17.0 through 12.1.0 all declare ^0.16.47 + # (npm view, 2026-10-06). mermaid touches katex in one place, a lazy + # `import("katex")` that calls the default export's renderToString() with + # { throwOnError, displayMode, output } for a `$$...$$` label. The 0.17 and + # 0.18 breaking changes (the internal __defineFunction API, prefixed + # internal CSS classes) touch neither that call nor the outer `.katex` + # class mermaid styles. Measured: a mermaid 11.16.1 flowchart with a + # `$$...$$` label renders MathML through katex 0.18.10 in Chromium, under + # the same initialize() options apps/docs/components/mermaid.tsx passes. + # The target resolves to 0.18.10, not 0.18.11: 0.18.11 is deprecated on + # npm ("Accidentally published with breaking changes"), and pnpm skips it. + # Transitive-only and docs-only: nothing publishable declares katex, so + # check-override-consistency.mjs's manifest rule has no declared range to + # hold in lockstep and says nothing about this entry (measured; neither + # census lists it: mermaid consumes it, and the bound clears the target + # floor). The floor is the advisory's 0.11.0; the bound is 0.19.0, the + # caret boundary of the 0.18 target line, per this block's header rule — + # never `<0.18.2`. + # Re-check when a mermaid release declares a katex range that admits + # 0.18.2: the entry then turns into a dedupe and stays as the floor. + 'katex@>=0.11.0 <0.19.0': '^0.18.2'