Skip to content

fix(deps): Bump mdast-util-to-hast to 13.2.1#19205

Merged
chargome merged 1 commit intodevelopfrom
cg/sec-848
Feb 6, 2026
Merged

fix(deps): Bump mdast-util-to-hast to 13.2.1#19205
chargome merged 1 commit intodevelopfrom
cg/sec-848

Conversation

@chargome
Copy link
Member

@chargome chargome commented Feb 6, 2026

  • Bumps transitive dependency mdast-util-to-hast from 13.0.2 to 13.2.1 to fix
    CVE-2025-66400 (unsanitized class attribute in markdown code blocks)

Ref: https://github.com/getsentry/sentry-javascript/security/dependabot/848

@chargome chargome self-assigned this Feb 6, 2026
@github-actions
Copy link
Contributor

github-actions bot commented Feb 6, 2026

Codecov Results 📊


Generated by Codecov Action

@github-actions
Copy link
Contributor

github-actions bot commented Feb 6, 2026

Codecov Results 📊

22 passed | ⏭️ 8 skipped | Total: 30 | Pass Rate: 73.33% | Execution Time: 9.42s

All tests are passing successfully.


Generated by Codecov Action

@getsentry getsentry deleted a comment from linear bot Feb 6, 2026
@github-actions
Copy link
Contributor

github-actions bot commented Feb 6, 2026

node-overhead report 🧳

Note: This is a synthetic benchmark with a minimal express app and does not necessarily reflect the real-world performance impact in an application.

Scenario Requests/s % of Baseline Prev. Requests/s Change %
GET Baseline 8,940 - 8,804 +2%
GET With Sentry 1,674 19% 1,655 +1%
GET With Sentry (error only) 6,065 68% 6,118 -1%
POST Baseline 1,215 - 1,174 +3%
POST With Sentry 600 49% 570 +5%
POST With Sentry (error only) 1,068 88% 1,054 +1%
MYSQL Baseline 3,355 - 3,324 +1%
MYSQL With Sentry 423 13% 433 -2%
MYSQL With Sentry (error only) 2,687 80% 2,626 +2%

View base workflow run

@chargome chargome marked this pull request as ready for review February 6, 2026 12:59
@linear
Copy link

linear bot commented Feb 6, 2026

@chargome chargome merged commit 1ee64f1 into develop Feb 6, 2026
400 of 419 checks passed
@chargome chargome deleted the cg/sec-848 branch February 6, 2026 13:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants