Skip to content

chore(deps-js)(deps-dev): bump markdownlint-cli2 from 0.15.0 to 0.22.1 in the node-dependencies group across 1 directory - #4

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/node-dependencies-c8f5c6fc1b
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/node-dependencies-c8f5c6fc1b

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 29, 2026

Copy link
Copy Markdown
Contributor

Bumps the node-dependencies group with 1 update in the / directory: markdownlint-cli2.

Updates markdownlint-cli2 from 0.15.0 to 0.22.1

Changelog

Sourced from markdownlint-cli2's changelog.

0.22.1

  • Update dependencies

0.22.0

  • Make --config parameter more flexible
  • Support TOML with --config parameter
  • Add --configPointer parameter
  • Update dependencies

0.21.0

  • Refactor options/configuration file loading
  • Update dependencies

0.20.0

  • Update dependencies (including markdownlint)

0.19.1

  • Update --format to avoid trailing newline
  • Update dependencies

0.19.0

  • Add --format parameter for editor integration
  • Update output formatters for severity warning
  • Explicitly version Docker containers for pre-commit
  • Update dependencies (including markdownlint)

0.18.1

  • Update dependencies (including markdownlint)

0.18.0

  • Use user ID in Docker containers for security
  • Update dependencies (including markdownlint)
  • Remove support for end-of-life Node 18

0.17.2

  • Update dependencies (including markdownlint)

0.17.1

  • Update dependencies (including markdownlint)

... (truncated)

Commits
  • 996abf6 Update to version 0.22.1.
  • 70b6875 Improve definition of OutputFormatterConfiguration type, minor other type twe...
  • 2cf5440 Add additional test case for previous commit fixing dotfile behavior.
  • 21c53ed Bump eslint from 10.2.0 to 10.2.1
  • b738aa0 Update removeIgnoredFiles use of micromatch to include dotfiles for consisten...
  • 24c04f4 Bump junit-report-builder from 5.1.1 to 5.1.2 in /formatter-junit
  • 650f208 Bump pnpm/action-setup from 5 to 6
  • 726eaab Bump eslint from 10.1.0 to 10.2.0
  • 1aa7579 Update indirect playwright dependencies to 1.59.1.
  • fee080d Bump @​playwright/test from 1.58.2 to 1.59.1
  • Additional commits viewable in compare view

@dependabot @github

dependabot Bot commented on behalf of github May 29, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: javascript. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@socket-security

socket-security Bot commented May 29, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addednpm/​markdownlint-cli2@​0.22.19910010085100

View full report

@socket-security

socket-security Bot commented May 29, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm entities is 91.0% likely obfuscated

Confidence: 0.91

Location: Package overview

From: ?npm/markdownlint-cli2@0.22.1npm/entities@4.5.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/entities@4.5.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm markdown-it is 91.0% likely obfuscated

Confidence: 0.91

Location: Package overview

From: ?npm/markdownlint-cli2@0.22.1npm/markdown-it@14.1.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/markdown-it@14.1.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@dependabot dependabot Bot changed the title chore(deps-js): bump markdownlint-cli2 from 0.15.0 to 0.22.1 in the node-dependencies group chore(deps-js): bump markdownlint-cli2 from 0.15.0 to 0.22.1 in the node-dependencies group across 1 directory May 29, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/node-dependencies-c8f5c6fc1b branch from 75b2f53 to 1bf5f93 Compare May 29, 2026 17:56
Bumps the node-dependencies group with 1 update in the / directory: [markdownlint-cli2](https://github.com/DavidAnson/markdownlint-cli2).


Updates `markdownlint-cli2` from 0.15.0 to 0.22.1
- [Changelog](https://github.com/DavidAnson/markdownlint-cli2/blob/main/CHANGELOG.md)
- [Commits](DavidAnson/markdownlint-cli2@v0.15.0...v0.22.1)

---
updated-dependencies:
- dependency-name: markdownlint-cli2
  dependency-version: 0.22.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: node-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps-js): bump markdownlint-cli2 from 0.15.0 to 0.22.1 in the node-dependencies group across 1 directory chore(deps-js)(deps-dev): bump markdownlint-cli2 from 0.15.0 to 0.22.1 in the node-dependencies group across 1 directory May 29, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/node-dependencies-c8f5c6fc1b branch from 1bf5f93 to 27b128a Compare May 29, 2026 19:13
@yacosta738 yacosta738 closed this May 30, 2026
@yacosta738
yacosta738 deleted the dependabot/npm_and_yarn/node-dependencies-c8f5c6fc1b branch May 30, 2026 13:26
@dependabot @github

dependabot Bot commented on behalf of github May 30, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

yacosta738 added a commit that referenced this pull request Jun 2, 2026
Four pre-existing issues caught by inline review of the PR-A stack.
Finding 5 (SESSION_NOT_FOUND redirect) was verified invalid and skipped —
the dashboard redirect is driven by currentUser, not by rejection codes.

## Finding 1: stream paths bypassed forbidden/rate-limit HTTP mapping

chat_completions_stream and anthropic_messages_stream were returning
SSE 200 with a generic internal_error event when the upstream
execute_stream_with_format returned a forbidden or rate_limited error.
This means a model-restricted key streaming chat completions got
200 + a confusing SSE error event instead of a clean HTTP 403.

Added Err-arms for is_forbidden() and is_rate_limited() in both stream
handlers so streaming and non-streaming requests share identical
auth/rate-limit behavior. New helpers map_forbidden_openai and
map_rate_limited return typed HttpError for the IntoResponse path.

## Finding 2: restrictions_from_headers failed open on missing headers

The function used unwrap_or_default() on header lookups, so a missing
x-authz-allowed-models or x-authz-allowed-providers header was silently
treated as 'unrestricted'. The authz middleware must always stamp these
headers, so a missing header indicates either a routing bug or a
middleware bypass — both should be loud, not silent.

Restructured into a parse_csv_header helper that returns
Result<Vec<String>, HttpError> and propagates AUTHZ_HEADER_MISSING
or AUTHZ_HEADER_INVALID 500 responses. Empty header value (public
subject) still maps to empty Vec, which the domain treats as
unrestricted.

## Finding 3: scopes_from_json rejected pre-#83 legacy scope strings

auth-sqlite used ApiKeyScope::parse (strict) in scopes_from_json, which
rejects any unknown scope string. Existing API keys created before
#83 with legacy values ('read', 'write') would fail to load.

Switched to ApiKeyScope::parse_lenient, which is the documented
method for reading from the database (accepts unknowns, logs warning).
Added regression test read_key_with_legacy_scope_string_is_preserved.

## Finding 4: required_scope fallback allowed POST with read-only key

required_scope returned Some("chat:read") for ANY /v1/* path that
wasn't /v1/providers/* or /v1/chat/* — regardless of HTTP method. This
meant a key with only the chat:read scope could hit POST /v1/messages
(Anthropic) and pass the authz check, then rely on downstream luck.

Updated the fallback to inspect the method: GET → chat:read, all
others → chat:write. The special-cases for /v1/providers* and
/v1/chat/* are preserved.

Added regression test
client_api_with_chat_read_scope_rejected_on_post_to_messages.
yacosta738 added a commit that referenced this pull request Jun 2, 2026
…nt (#89)

* feat(api-key): typed ApiKeyScope with canonical scope values (#83)

Add KnownScope enum with five canonical values: chat:read, chat:write,
providers:read, providers:write, admin.

ApiKeyScope::parse now rejects unknown values with UnknownScope error.
ApiKeyScope::parse_lenient is introduced for DB reads — accepts any
non-empty value and emits a tracing::warn for unrecognised scopes.

ManageApiKeys::create and update validate all scopes before touching
the repository.

Fixes pre-existing sha2 0.11 compilation breakage in login.rs,
validate_session.rs, and auth.rs.

* feat(authz): scope enforcement per route class in client API policy (#84)

Add required_scope(method, path) mapping routes under /v1/* to their
canonical scope requirement. Add check_scope helper that allows requests
when the subject holds the required scope or the admin superset scope,
and rejects with HTTP 403 INSUFFICIENT_SCOPE otherwise.

Thread method and path through evaluate_policy and client_api_policy.
Update env-fallback credentials to use canonical scope names.
Update all affected tests to use canonical scope values.

* fix: apply CodeRabbit auto-fixes

Fixed 8 file(s) based on 3 unresolved review comments.

Co-authored-by: CodeRabbit <noreply@coderabbit.ai>

* feat(api-key): add allowed_models/allowed_providers and enforce in routing (#85, #86) (#90)

* chore(deps-rust)(deps): bump axum-test from 15.7.4 to 20.1.0 (#78)

Bumps [axum-test](https://github.com/JosephLenton/axum-test) from 15.7.4 to 20.1.0.
- [Release notes](https://github.com/JosephLenton/axum-test/releases)
- [Commits](https://github.com/JosephLenton/axum-test/commits)

---
updated-dependencies:
- dependency-name: axum-test
  dependency-version: 20.1.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* feat(api-key): add allowed_models and allowed_providers restriction fields (#85)

* feat(routing): enforce allowed_models and allowed_providers restrictions (#86)

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* feat(deps): add hex crate version 0.4.3 to Cargo.lock

* fix(dashboard): update API key scope options to canonical chat:read/chat:write

The dashboard was still emitting pre-#83 scope values ('read', 'write') in
the create/edit modals, which the backend now rejects with 400
'unknown API key scope'.

This was surfaced by 'just ci-local' failing the Playwright e2e suite
after #83/#84 landed. Without this fix, every dashboard user creating
an API key via the UI would have hit the same 400 error.

- ApiKeysView.vue: dropdown values updated to canonical scopes
- api-keys.spec.ts: helper defaults + 2 call sites updated; UI selector
  tightened to '^chat read$' to avoid accidental matches

* fix(authz): address code review findings (#1-#4)

Four pre-existing issues caught by inline review of the PR-A stack.
Finding 5 (SESSION_NOT_FOUND redirect) was verified invalid and skipped —
the dashboard redirect is driven by currentUser, not by rejection codes.

## Finding 1: stream paths bypassed forbidden/rate-limit HTTP mapping

chat_completions_stream and anthropic_messages_stream were returning
SSE 200 with a generic internal_error event when the upstream
execute_stream_with_format returned a forbidden or rate_limited error.
This means a model-restricted key streaming chat completions got
200 + a confusing SSE error event instead of a clean HTTP 403.

Added Err-arms for is_forbidden() and is_rate_limited() in both stream
handlers so streaming and non-streaming requests share identical
auth/rate-limit behavior. New helpers map_forbidden_openai and
map_rate_limited return typed HttpError for the IntoResponse path.

## Finding 2: restrictions_from_headers failed open on missing headers

The function used unwrap_or_default() on header lookups, so a missing
x-authz-allowed-models or x-authz-allowed-providers header was silently
treated as 'unrestricted'. The authz middleware must always stamp these
headers, so a missing header indicates either a routing bug or a
middleware bypass — both should be loud, not silent.

Restructured into a parse_csv_header helper that returns
Result<Vec<String>, HttpError> and propagates AUTHZ_HEADER_MISSING
or AUTHZ_HEADER_INVALID 500 responses. Empty header value (public
subject) still maps to empty Vec, which the domain treats as
unrestricted.

## Finding 3: scopes_from_json rejected pre-#83 legacy scope strings

auth-sqlite used ApiKeyScope::parse (strict) in scopes_from_json, which
rejects any unknown scope string. Existing API keys created before
#83 with legacy values ('read', 'write') would fail to load.

Switched to ApiKeyScope::parse_lenient, which is the documented
method for reading from the database (accepts unknowns, logs warning).
Added regression test read_key_with_legacy_scope_string_is_preserved.

## Finding 4: required_scope fallback allowed POST with read-only key

required_scope returned Some("chat:read") for ANY /v1/* path that
wasn't /v1/providers/* or /v1/chat/* — regardless of HTTP method. This
meant a key with only the chat:read scope could hit POST /v1/messages
(Anthropic) and pass the authz check, then rely on downstream luck.

Updated the fallback to inspect the method: GET → chat:read, all
others → chat:write. The special-cases for /v1/providers* and
/v1/chat/* are preserved.

Added regression test
client_api_with_chat_read_scope_rejected_on_post_to_messages.

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
Co-authored-by: CodeRabbit <noreply@coderabbit.ai>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant