Skip to content

Remove vulnerable transitive dependencies braces and sprintf-js. - #21

Merged
koculu merged 1 commit into
mainfrom
remove-vulnerable-transitive-deps
Oct 7, 2026
Merged

koculu merged 1 commit into
mainfrom
remove-vulnerable-transitive-deps

Conversation

@koculu

@koculu koculu commented Oct 7, 2026

Copy link
Copy Markdown
Member

Summary

Removes vulnerable transitive dependencies braces and sprintf-js by simplifying HTML minification and updating frontmatter parsing.

Changes

  • Calls html-minifier-next directly, preserving the existing engine, version, and minification options.
  • Replaces gray-matter with maintained @11ty/gray-matter, removing the outdated YAML dependency chain.
  • Regenerates yarn.lock; neither vulnerable package remains.

The parser update removes JavaScript frontmatter support and changes some YAML scalar interpretation, including unquoted dates and legacy numeric formats. Comparing all 122 YAML frontmatter blocks in the frontend and sample content found no differences.

Validation: 52 relevant tests passed, TypeScript and lint checks passed, and immutable Yarn install succeeded.

@koculu
koculu merged commit ce52306 into main Oct 7, 2026
2 checks passed
@koculu
koculu deleted the remove-vulnerable-transitive-deps branch October 7, 2026 23:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant