You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Upgrade the docs development dependency Mintlify to 4.2.933 on main, independently of the Better Auth/root-security stack. The diff contains only apps/docs/package.json and bun.lock. It does not include auth source changes, root manifest overrides, or the commits from #1719/#1724.
Archive security fix
4.2.933 is the earliest stable Mintlify parent whose published dependency graph both removes Puppeteer/extract-zip and uses patched tar 7.5.21. extract-zip has no patched release for High GHSA-jmr9-qjv8-65gv / GHSA-7pqw-9j4j-h8q3, so upgrading its parent removes the vulnerable chain rather than forcing a nonexistent patch. Mintlify's own previewing package handles the tar 6→7 migration.
Also patch compatible vulnerable resolutions changed by the Mintlify upgrade: adm-zip 0.6.1, js-yaml 4.3.2, minimatch 3.1.4, brace-expansion 1.1.18, path-to-regexp 0.1.13, and picomatch 2.3.2. Preserve unrelated Bun-type versions. No docs content, dev command, application behavior, or test files are changed.
Fresh advisory range matching finds zero High/Critical matches among this PR's changed docs resolutions; extract-zip/Puppeteer are absent and tar is 7.5.21. This is not a claim that main's entire dependency graph is clean: Better Auth and other pre-existing workspace findings remain outside this independent docs PR. Exact Dependabot alert numbers still await alert-read access (the integration returns HTTP 403).
Validation
Passed frozen Bun install, diff check, tar archive roundtrip, web/AI SDK/tools/memory-graph production builds, lib/hooks/AI SDK/memory-graph and MCP server typechecks, and existing tests: 4 AI SDK, 101 tools, 197 graph, 20 MCP unit and 11 active MCP e2e tests. Skipped credential-dependent tests remain skipped. Tools' 146 full-typecheck diagnostics exactly match the post-build baseline. Auth source and the root package manifest match main byte-for-byte.
No docs build/typecheck/test scripts exist. The inherited local Mintlify duplicate-React error remains; using a scratch-only resolution loader, fresh runs of the upgraded CLI now pass full build validation and broken-link checking against the current hosted OpenAPI. The live definition no longer includes the invalid undocumented security response seen in the failed CI run. No unrelated React, API-schema, docs-link or test change was needed.
Mintlify's required internal MDX dependency graph changes major versions; docs content is unchanged and the validation limitation above is explicit.
CI rerun
A CI-only empty commit triggers fresh checks after the hosted OpenAPI input changed. Mintlify link-rot now succeeds with zero broken links; full docs build validation also passes locally. Mintlify Deployment is skipped with "No changes to preview" because the source tree is unchanged, so this is not evidence of a new hosted preview deployment. Other checks are completing normally.
The hosted OpenAPI input has changed since the failed Mintlify run: the invalid undocumented /v3/settings/security response is no longer present. Fresh runs of the upgraded CLI's full build validation and broken-link check now pass against the unchanged docs content. The two links resolve once API pages are generated from the valid schema. Triggering a fresh CI run with an empty CI-only commit because the integration returns HTTP 403 for Mintlify check rerun requests; no API behavior, docs links, or test files need changing.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Upgrade the docs development dependency Mintlify to 4.2.933 on main, independently of the Better Auth/root-security stack. The diff contains only apps/docs/package.json and bun.lock. It does not include auth source changes, root manifest overrides, or the commits from #1719/#1724.
Archive security fix
4.2.933 is the earliest stable Mintlify parent whose published dependency graph both removes Puppeteer/extract-zip and uses patched tar 7.5.21. extract-zip has no patched release for High GHSA-jmr9-qjv8-65gv / GHSA-7pqw-9j4j-h8q3, so upgrading its parent removes the vulnerable chain rather than forcing a nonexistent patch. Mintlify's own previewing package handles the tar 6→7 migration.
Also patch compatible vulnerable resolutions changed by the Mintlify upgrade: adm-zip 0.6.1, js-yaml 4.3.2, minimatch 3.1.4, brace-expansion 1.1.18, path-to-regexp 0.1.13, and picomatch 2.3.2. Preserve unrelated Bun-type versions. No docs content, dev command, application behavior, or test files are changed.
Fresh advisory range matching finds zero High/Critical matches among this PR's changed docs resolutions; extract-zip/Puppeteer are absent and tar is 7.5.21. This is not a claim that main's entire dependency graph is clean: Better Auth and other pre-existing workspace findings remain outside this independent docs PR. Exact Dependabot alert numbers still await alert-read access (the integration returns HTTP 403).
Validation
Passed frozen Bun install, diff check, tar archive roundtrip, web/AI SDK/tools/memory-graph production builds, lib/hooks/AI SDK/memory-graph and MCP server typechecks, and existing tests: 4 AI SDK, 101 tools, 197 graph, 20 MCP unit and 11 active MCP e2e tests. Skipped credential-dependent tests remain skipped. Tools' 146 full-typecheck diagnostics exactly match the post-build baseline. Auth source and the root package manifest match main byte-for-byte.
No docs build/typecheck/test scripts exist. The inherited local Mintlify duplicate-React error remains; using a scratch-only resolution loader, fresh runs of the upgraded CLI now pass full build validation and broken-link checking against the current hosted OpenAPI. The live definition no longer includes the invalid undocumented security response seen in the failed CI run. No unrelated React, API-schema, docs-link or test change was needed.
Mintlify's required internal MDX dependency graph changes major versions; docs content is unchanged and the validation limitation above is explicit.
CI rerun
A CI-only empty commit triggers fresh checks after the hosted OpenAPI input changed. Mintlify link-rot now succeeds with zero broken links; full docs build validation also passes locally. Mintlify Deployment is skipped with "No changes to preview" because the source tree is unchanged, so this is not evidence of a new hosted preview deployment. Other checks are completing normally.