Skip to content

deps: remediate website vulnerabilities - #978

Merged
Liangying.Wei (vicancy) merged 1 commit into
mainfrom
vicancy/fix-website-dependencies
Aug 14, 2026
Merged

deps: remediate website vulnerabilities#978
Liangying.Wei (vicancy) merged 1 commit into
mainfrom
vicancy/fix-website-dependencies

Conversation

@vicancy

Copy link
Copy Markdown
Member

Summary

  • upgrade the legacy code-highlighting chain and migrate Prism theme imports to the current API
  • pin patched versions across the Docusaurus development and build dependency graph
  • remove 25 of the website lockfile's 28 current Dependabot alerts

Remaining upstream blockers

  • image-size has two high-severity advisories with no patched release
  • nanoid 3.3.18 is listed as patched by GitHub but is not yet available from the approved npm feed

Validation

  • Yarn frozen-lockfile install
  • TypeScript typecheck
  • Docusaurus production build

Upgrade the website dependency graph, migrate Prism theme imports, and retain only advisories that currently lack an installable patched version.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 6897cee9-248f-47db-a739-ab3a51b94527
@vicancy
Liangying.Wei (vicancy) enabled auto-merge (squash) August 14, 2026 10:36
@vicancy
Liangying.Wei (vicancy) merged commit 3304ff4 into main Aug 14, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants