Skip to content

fix(deps): patch source-map-js and Mermaid KaTeX - #521

Merged
jsgrrchg merged 1 commit into
mainfrom
fix/dependabot-source-map-katex
Oct 8, 2026
Merged

jsgrrchg merged 1 commit into
mainfrom
fix/dependabot-source-map-katex

Conversation

@jsgrrchg

@jsgrrchg jsgrrchg commented Oct 8, 2026

Copy link
Copy Markdown
Owner

The web clipper locked vulnerable source-map-js@1.2.1, and Mermaid bundled katex@0.16.47 even though the desktop editor already used patched KaTeX. Pin source-map-js to 1.2.2 through the existing pnpm workspace overrides and make Mermaid reuse the desktop KaTeX dependency (currently locked at 0.18.2), removing the vulnerable nested copy.

Addresses Dependabot alerts #145 and #143. Upstream advisories: source-map-js and KaTeX.

Validation:

  • Clean desktop install (npm@11 ci) and frozen clipper install (pnpm@10.33.0 install --frozen-lockfile) passed.
  • Clipper pnpm run check: TypeScript, 25 tests, and Chrome/Firefox builds passed.
  • Desktop npm run lint and npm run build passed.
  • Desktop full suite: 2,636 tests passed; one UnifiedBar test timed out at the default 5 seconds. A focused rerun with --maxWorkers=2 passed all 42 tests across UnifiedBar, Mermaid renderer, block previews, and Mermaid file preview.
  • Real Chromium smoke passed for a normal Mermaid flowchart and a flowchart with two formula labels using the actual application renderer.
  • Confirmed Mermaid resolves KaTeX 0.18.2; inherited trust cannot enable JavaScript links or external images, while ordinary fractions still render.
  • Confirmed all three clipper dependency paths resolve source-map-js 1.2.2 and normal source-map lookups work.

The Mermaid override crosses its declared KaTeX minor-version range; the real formula rendering smoke and desktop build cover this compatibility concern.

@jsgrrchg
jsgrrchg merged commit 58227f3 into main Oct 8, 2026
21 checks passed
@jsgrrchg
jsgrrchg deleted the fix/dependabot-source-map-katex branch October 9, 2026 23:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant