Skip to content

Fix Dependabot alerts: pin js-yaml to 4.3.2 - #35

Merged
vharseko merged 1 commit into
OpenIdentityPlatform:masterfrom
vharseko:dependabot-js-yaml
Oct 1, 2026
Merged

vharseko merged 1 commit into
OpenIdentityPlatform:masterfrom
vharseko:dependabot-js-yaml

Conversation

@vharseko

Copy link
Copy Markdown
Member

Closes the open Dependabot alerts #25–#28 (1 medium, 3 high): quadratic CPU consumption in js-yaml merge-key and !!omap handling.

Why an override

js-yaml@4.1.1 comes in transitively through antora@3.1.15, whose packages (@antora/playbook-builder, @antora/content-aggregator, @antora/ui-loader) require js-yaml ~4.1. All fixes land only in 4.2.0–4.3.2, so Dependabot cannot raise it within that range.

package.json now overrides js-yaml to 4.3.2; package-lock.json is updated accordingly. The version stays on the 4.x line, so the API Antora uses is unchanged. Moving to antora@3.2.0 (which depends on js-yaml ~5.4) would also clear the alerts, but it is a larger change to the site build and is left out of this PR.

Verification

  • npm ls js-yaml — all three @antora/* consumers resolve to 4.3.2 overridden.
  • npm audit — found 0 vulnerabilities.
  • npx antora antora-playbook.yml — exit 0; the 4 Antora errors it reports are the known ones from the product repositories (the same list as .github/build-baseline/antora-errors.txt in [#25] CI: build pull requests and make the site build reproducible #28), no new ones.

antora 3.1.15 depends on js-yaml ~4.1, and 4.1.1 is affected by
GHSA advisories on quadratic CPU use in merge keys and !!omap
(Dependabot alerts OpenIdentityPlatform#25-OpenIdentityPlatform#28). Override it to 4.3.2, the first
release with all fixes; the 4.x API is unchanged and the site
builds with the same known Antora errors as before.
@vharseko vharseko added dependencies Updates or pins of third-party dependencies security Fixes for security vulnerabilities or advisories labels Sep 30, 2026
@vharseko
vharseko merged commit ee1a59f into OpenIdentityPlatform:master Oct 1, 2026
vharseko added a commit that referenced this pull request Oct 2, 2026
…nu (#30)

Fixes #22

## Changes
- **`ROOT/modules/ROOT/pages/index.adoc`** (start page):
- an "API Reference (Javadoc)" link at the end of the guide list of each
of the four products;
- a new "API Reference (Javadoc)" section (`#api-reference`) with
*Products* (OpenDJ, OpenAM, OpenIG, OpenIDM) and *Libraries*:
**OpenICF** and **Commons**, whose Javadoc was reachable only by URL.

The links are root-relative (`/openam/apidocs/index.html`), because the
Javadoc is not an Antora page but is copied into the site by `npm run
copyApiDocs`.
- **`supplemental-ui/partials/header-content.hbs`**: a divider and an
"API Reference (Javadoc)" entry in the Projects menu, pointing to that
section.

Component navigation is not changed: the product release workflows
replace `<product>/modules` (`rm -rf`) on every docs upload, so an entry
added there in this repository would be lost; it would have to come from
the product repositories.

## Verification
Local Antora build of this branch (with `copyApiDocs`):
- all six targets (`openam`, `opendj`, `openidm`, `openig`, `openicf`,
`commons` `/apidocs/index.html`) exist in the generated site;
- the menu entry resolves from every page, e.g. `./#api-reference` on
the start page and `../../#api-reference` on `openam/admin-guide/`;
- `lychee --offline`: no broken link on the start page; the site total
is unchanged (45, all known and tracked);
- no new Antora errors;
- the branch is rebased onto `master` after #27 and #35, without
conflicts.

In CI, a missing `<dir>/apidocs/index.html` target is caught by the
lychee check of #28; a renamed `#api-reference` anchor by its
`--include-fragments` run proposed in #36.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Updates or pins of third-party dependencies security Fixes for security vulnerabilities or advisories

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants