Skip to content

chore: update markdownlint-cli2 to v0.21.0 to fix CVE-2025-64718#55921

Open
PHILLIPS71 wants to merge 1 commit intofacebook:mainfrom
PHILLIPS71:chore/deps-markdownlint-cli2
Open

chore: update markdownlint-cli2 to v0.21.0 to fix CVE-2025-64718#55921
PHILLIPS71 wants to merge 1 commit intofacebook:mainfrom
PHILLIPS71:chore/deps-markdownlint-cli2

Conversation

@PHILLIPS71
Copy link

@PHILLIPS71 PHILLIPS71 commented Mar 5, 2026

Summary:

This PR updates markdownlint-cli2 to v0.21.0, which includes a patch that resolves the security vulnerability CVE-2025-64718.

The underlying issue was caused by markdownlint-cli2 depending on js-yaml@4.1.0. The update ensures that the dependent js-yaml is upgraded to a version that no longer exposes the vulnerability.

Changelog:

[GENERAL] [SECURITY] - updated markdownlint-cli2 to v0.21.0 to fix CVE-2025-64718 by upgrading js-yaml dependency

Test Plan:

image image

@meta-cla meta-cla bot added the CLA Signed This label is managed by the Facebook bot. Authors need to sign the CLA before a PR can be reviewed. label Mar 5, 2026
@facebook-github-bot facebook-github-bot added the Shared with Meta Applied via automation to indicate that an Issue or Pull Request has been shared with the team. label Mar 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CLA Signed This label is managed by the Facebook bot. Authors need to sign the CLA before a PR can be reviewed. Shared with Meta Applied via automation to indicate that an Issue or Pull Request has been shared with the team.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants