Skip to content

chore: replace gray-matter with shared frontmatter extraction - #172

Open
raymondboswel wants to merge 2 commits into
kobaltedev:mainfrom
raymondboswel:chore/remove-gray-matter
Open

raymondboswel wants to merge 2 commits into
kobaltedev:mainfrom
raymondboswel:chore/remove-gray-matter

Conversation

@raymondboswel

@raymondboswel raymondboswel commented Oct 1, 2026 •

Copy link
Copy Markdown

I'm currently using SolidBase to host some internal documentation. The gray-matter dependency included in the project has been flagged by our Cyber security team as containing vulnerabilities. I investigated the library, and it appears to be unmaintained, with many open PRs, and the last merge about 5 years ago. I considered trying to contact the maintainer, but dropping the dependency here seemed like a better option.

The solution was implemented by Opus 5.5 and reviewed by Sol 6.1.

I've run pnpm dev & pnpm dev:docs locally and could not spot any regressions.

Summary

  • Remove gray-matter and its unused transitive dependencies.
  • Extract metadata using the existing remark-frontmatter, YAML, and TOML dependencies, matching the Markdown pipeline defaults and explicitly configured formats.
  • Honor nested unified presets and registration order, and pass Markdown configuration into sitemap and LLM indexing.
  • Add a frontmatter option to filesystem sidebar helpers and regression coverage for empty blocks, line endings, configured TOML, titles, and exclusions.

Validation

  • pnpm test tests/config: 116 tests passed across 21 files.
  • Biome checks for affected files and git diff --check: passed.
  • Full-suite run earlier in development: two preview tests failed because the local installation could not locate @babel/preset-typescript.
  • Typechecking reports three existing errors in unchanged files: src/config/vite-plugin/index.ts and src/default-theme/index.ts.

raymondboswel and others added 2 commits October 2, 2026 07:12
gray-matter is unmaintained and pulls in js-yaml 3.x, which triggers
dependency scanning alerts. It was only used to read frontmatter data
for the filesystem sidebar and the routes index.

Add a small parser that reuses the `yaml` and `toml` libraries already
used by the MDX pipeline, so all frontmatter is parsed consistently
(TOML `+++` blocks are now also picked up by the sidebar and routes
index) and there is no `---js` eval path.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@netlify

netlify Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for solidbase ready!

Name Link
🔨 Latest commit 48758b9
🔍 Latest deploy log https://app.netlify.com/projects/solidbase/deploys/6abecd14e6bcf400088b955e
😎 Deploy Preview https://deploy-preview-172--solidbase.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
Lighthouse
Lighthouse
1 paths audited
Performance: 90 (🔴 down 6 from production)
Accessibility: 100 (no change from production)
Best Practices: 100 (no change from production)
SEO: 100 (no change from production)
PWA: -
View the detailed breakdown and full score reports
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@raymondboswel
raymondboswel marked this pull request as ready for review October 1, 2026 21:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant