Skip to content

fix(docs): remove vulnerable ZIP extractor and patch tar via Mintlify - #1725

Closed
Dhravya wants to merge 2 commits into
capy/upgrade-better-auth-tofrom
capy/docs-security-followup
Closed

Dhravya wants to merge 2 commits into
capy/upgrade-better-auth-tofrom
capy/docs-security-followup

Conversation

@Dhravya

@Dhravya Dhravya commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

Pin the docs development dependency Mintlify to 4.2.933 and regenerate only its required dependency graph, on top of #1724. No docs content, deployment configuration, application code or tests change. Existing docs dev script behavior (bunx mintlify@latest) is left untouched.

Why this parent upgrade

extract-zip 2.0.1 has no published patched release for High GHSA-jmr9-qjv8-65gv / GHSA-7pqw-9j4j-h8q3, so overriding it cannot solve the alerts. Published Mintlify/CLI/link-rot/scraping/previewing metadata establishes 4.2.933 as the earliest stable Mintlify parent that removes Puppeteer and therefore extract-zip, while using patched tar 7.5.21. Its previewing code owns the tar 6→7 API migration; we do not force a major tar override on the old parent.

Tar coverage includes Critical GHSA-23hp-3jrh-7fpw and High archive traversal/recursion advisories through GHSA-r292-9mhp-454m. Retain the root's patched js-yaml 4.3.2 rather than accepting Mintlify's vulnerable pinned 4.3.1. Preserve unrelated Bun types. The final combined root graph has zero High/Critical locked-version matches in a fresh npm advisory audit; extract-zip and Puppeteer are absent.

Exact Dependabot alert numbers await access: the integration returns HTTP 403 for the repository alerts API. Map the GHSA IDs to actual repository alert numbers before SOC 2 sign-off.

Stack

Review/merge auth #1719 → root #1724 → this docs layer. Separate lockfile PRs (#1720, #1721, #1722 and #1723) are independent.

Validation and limitations

Frozen Bun install, git diff --check, tar gzip archive roundtrip, and Sharp PNG resize pass. All shared consumers were revalidated after this graph change: web/AI SDK/tools/memory-graph builds; lib/hooks/AI SDK/memory-graph and MCP server typechecks; 4 AI SDK, 101 tools, 197 graph, 20 MCP unit and 11 active MCP e2e tests pass. Tools' remaining full-typecheck diagnostics match the post-build baseline exactly. No docs build/typecheck/test scripts are defined.

The local Mintlify CLI encounters duplicate-React hook errors both before and after the upgrade. A scratch-only React resolution loader gets the patched validator past that inherited issue, but strict docs validation then rejects the externally hosted OpenAPI document (api.supermemory.ai/v4/openapi): /v3/settings/security PATCH response 200 lacks a required description. Thus a successful docs validation/build is not claimed. Neither that external API schema nor unrelated React resolution was changed in this security PR.

Mintlify's internal MDX packages change major versions as part of the required parent graph; docs content is unchanged, and full docs validation remains limited as above.

@capy-ai
capy-ai Bot added this pull request to stack #1726 September 29, 2026 21:50
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
supermemory-app d1488f4 Commit Preview URL

Branch Preview URL
Sep 29 2026, 09:51 PM

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
✅ Deployment successful!
View logs
supermemory-mcp d1488f4 Sep 29 2026, 09:52 PM

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​mintlify@​4.2.407 ⏵ 4.2.933100 +4510093 -110090

View full report

Base automatically changed from capy/root-security-followup to capy/upgrade-better-auth-to September 29, 2026 22:29
@capy-ai

capy-ai Bot commented Sep 29, 2026

Copy link
Copy Markdown

Recreated as #1727 on the updated auth branch, which already contains squash-merged #1724. The replacement has only the docs manifest/lockfile diff and no obsolete root commit. Its Git tree exactly matches the validated docs tree; fresh frozen install, web build, tar smoke test and zero High/Critical lock matches passed. Closing this superseded PR to avoid reviewing the conflicting stack history.

@capy-ai capy-ai Bot closed this Sep 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant