chore: replace gray-matter with shared frontmatter extraction - #172
Open
raymondboswel wants to merge 2 commits into
Open
raymondboswel wants to merge 2 commits into
raymondboswel wants to merge 2 commits into
Conversation
gray-matter is unmaintained and pulls in js-yaml 3.x, which triggers dependency scanning alerts. It was only used to read frontmatter data for the filesystem sidebar and the routes index. Add a small parser that reuses the `yaml` and `toml` libraries already used by the MDX pipeline, so all frontmatter is parsed consistently (TOML `+++` blocks are now also picked up by the sidebar and routes index) and there is no `---js` eval path. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
✅ Deploy Preview for solidbase ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
raymondboswel
marked this pull request as ready for review
October 1, 2026 21:33
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

I'm currently using SolidBase to host some internal documentation. The gray-matter dependency included in the project has been flagged by our Cyber security team as containing vulnerabilities. I investigated the library, and it appears to be unmaintained, with many open PRs, and the last merge about 5 years ago. I considered trying to contact the maintainer, but dropping the dependency here seemed like a better option.
The solution was implemented by Opus 5.5 and reviewed by Sol 6.1.
I've run
pnpm dev&pnpm dev:docslocally and could not spot any regressions.Summary
Validation
pnpm test tests/config: 116 tests passed across 21 files.git diff --check: passed.