Skip to content

fix(docs): remove vulnerable ZIP extractor and patch tar via Mintlify - #1727

Merged
Dhravya merged 2 commits into
mainfrom
capy/docs-security-recreated
Sep 29, 2026
Merged

Dhravya merged 2 commits into
mainfrom
capy/docs-security-recreated

Conversation

@Dhravya

@Dhravya Dhravya commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

Upgrade the docs development dependency Mintlify to 4.2.933 on main, independently of the Better Auth/root-security stack. The diff contains only apps/docs/package.json and bun.lock. It does not include auth source changes, root manifest overrides, or the commits from #1719/#1724.

Archive security fix

4.2.933 is the earliest stable Mintlify parent whose published dependency graph both removes Puppeteer/extract-zip and uses patched tar 7.5.21. extract-zip has no patched release for High GHSA-jmr9-qjv8-65gv / GHSA-7pqw-9j4j-h8q3, so upgrading its parent removes the vulnerable chain rather than forcing a nonexistent patch. Mintlify's own previewing package handles the tar 6→7 migration.

Also patch compatible vulnerable resolutions changed by the Mintlify upgrade: adm-zip 0.6.1, js-yaml 4.3.2, minimatch 3.1.4, brace-expansion 1.1.18, path-to-regexp 0.1.13, and picomatch 2.3.2. Preserve unrelated Bun-type versions. No docs content, dev command, application behavior, or test files are changed.

Fresh advisory range matching finds zero High/Critical matches among this PR's changed docs resolutions; extract-zip/Puppeteer are absent and tar is 7.5.21. This is not a claim that main's entire dependency graph is clean: Better Auth and other pre-existing workspace findings remain outside this independent docs PR. Exact Dependabot alert numbers still await alert-read access (the integration returns HTTP 403).

Validation

Passed frozen Bun install, diff check, tar archive roundtrip, web/AI SDK/tools/memory-graph production builds, lib/hooks/AI SDK/memory-graph and MCP server typechecks, and existing tests: 4 AI SDK, 101 tools, 197 graph, 20 MCP unit and 11 active MCP e2e tests. Skipped credential-dependent tests remain skipped. Tools' 146 full-typecheck diagnostics exactly match the post-build baseline. Auth source and the root package manifest match main byte-for-byte.

No docs build/typecheck/test scripts exist. The inherited local Mintlify duplicate-React error remains; using a scratch-only resolution loader, fresh runs of the upgraded CLI now pass full build validation and broken-link checking against the current hosted OpenAPI. The live definition no longer includes the invalid undocumented security response seen in the failed CI run. No unrelated React, API-schema, docs-link or test change was needed.

Mintlify's required internal MDX dependency graph changes major versions; docs content is unchanged and the validation limitation above is explicit.

CI rerun

A CI-only empty commit triggers fresh checks after the hosted OpenAPI input changed. Mintlify link-rot now succeeds with zero broken links; full docs build validation also passes locally. Mintlify Deployment is skipped with "No changes to preview" because the source tree is unchanged, so this is not evidence of a new hosted preview deployment. Other checks are completing normally.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
✅ Deployment successful!
View logs
supermemory-mcp 4e6a3df Sep 29 2026, 11:38 PM

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
supermemory-app 4e6a3df Commit Preview URL

Branch Preview URL
Sep 29 2026, 11:37 PM

@socket-security

socket-security Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​mintlify@​4.2.407 ⏵ 4.2.933100 +4510093 -110090

View full report

@Dhravya
Dhravya force-pushed the capy/docs-security-recreated branch from 40318b8 to 11df44b Compare September 29, 2026 23:01
@capy-ai
capy-ai Bot changed the base branch from capy/upgrade-better-auth-to to main September 29, 2026 23:03
@mintlify

mintlify Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated
supermemory 🔴 Failed – Sep 29, 2026, 11:03 PM

💡 Tip: Enable Automations to automatically generate PRs for you.

@capy-ai

capy-ai Bot commented Sep 29, 2026

Copy link
Copy Markdown

The hosted OpenAPI input has changed since the failed Mintlify run: the invalid undocumented /v3/settings/security response is no longer present. Fresh runs of the upgraded CLI's full build validation and broken-link check now pass against the unchanged docs content. The two links resolve once API pages are generated from the valid schema. Triggering a fresh CI run with an empty CI-only commit because the integration returns HTTP 403 for Mintlify check rerun requests; no API behavior, docs links, or test files need changing.

@Dhravya
Dhravya merged commit 0c74b55 into main Sep 29, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant