diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index a05deaae..640a951d 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -32,7 +32,7 @@ jobs: strace --version - name: Install independent vector tool - uses: taiki-e/install-action@41049aa56687c35e0afa74eed4f09cec4f9afabf # v2.85.2 + uses: taiki-e/install-action@83ac0ad63c0167e6f06796fab0fce28db1bf3db0 # v2.87.22 with: tool: b3sum@1.8.5 @@ -177,7 +177,7 @@ jobs: run: rustup show - name: Install dependency policy tools - uses: taiki-e/install-action@41049aa56687c35e0afa74eed4f09cec4f9afabf # v2.85.2 + uses: taiki-e/install-action@83ac0ad63c0167e6f06796fab0fce28db1bf3db0 # v2.87.22 with: tool: cargo-deny@0.18.9,cargo-audit@0.22.0 diff --git a/CHANGELOG.md b/CHANGELOG.md index 1a1d8925..d51e0c06 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -8,6 +8,10 @@ after its public API and format compatibility policies are established. ## [Unreleased] +- Update the repository-only YAML parser to yaml-rust2 0.13.0 and refresh its dependency admission, retaining existing workflow and Dependabot refusal expectations (#103). + +- Update the development-only Markdown validation graph and exact admission policy to markdownlint-cli2 0.23.3, addressing the js-yaml, smol-toml and markdown-it advisories while documenting the separate remaining braces advisory (#106). + - Current durable-surface documentation distinguishes delivered recovery, fenced authenticated reads and explicit verification from pending ingestion, GC, compaction and general candidate-catalog retained-closure admission (#130). - Retention verification refuses observed file or symlink substitutions of a selected namespace directory as typed corruption, preserving the original selected root evidence (#114). diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 8486e4f4..0eae802c 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -31,7 +31,7 @@ before creating documentation or substantially changing an existing page. It does not require rewriting pages that are merely below the bar; apply it when a change would otherwise add new documentation debt. -Documentation validation uses `markdownlint-cli2` 0.23.2, `lychee` 0.21.0, +Documentation validation uses `markdownlint-cli2` 0.23.3, `lychee` 0.21.0, and `actionlint` 1.7.12. Install those exact versions, then run the repository-owned checks from the repository root: diff --git a/Cargo.lock b/Cargo.lock index f5b15c6b..5f340ce5 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -260,18 +260,18 @@ dependencies = [ [[package]] name = "hashbrown" -version = "0.16.1" +version = "0.17.1" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "841d1cc9bed7f9236f321df977030373f4a4163ae1a7dbfe1a51a2c1a51d9100" +checksum = "ed5909b6e89a2db4456e54cd5f673791d7eca6732202bbf2a9cc504fe2f9b84a" dependencies = [ "foldhash", ] [[package]] name = "hashlink" -version = "0.11.1" +version = "0.12.2" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "824e001ac4f3012dd16a264bec811403a67ca9deb6c102fc5049b32c4574b35f" +checksum = "a596f1b20ed2cc5ecac41a164aaebc7258057060f06c0cf7a2ba3991ee7990fb" dependencies = [ "hashbrown", ] @@ -749,9 +749,9 @@ dependencies = [ [[package]] name = "yaml-rust2" -version = "0.11.0" +version = "0.13.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "631a50d867fafb7093e709d75aaee9e0e0d5deb934021fcea25ac2fe09edc51e" +checksum = "57e5b818a27a4cd30884ea380857a5e56f7ec3ba24a3990a3cc0b95af3238e18" dependencies = [ "arraydeque", "hashlink", diff --git a/docs/Documentation Standards.md b/docs/Documentation Standards.md index 53a75189..3087c84d 100644 --- a/docs/Documentation Standards.md +++ b/docs/Documentation Standards.md @@ -541,7 +541,7 @@ git diff --check git diff --cached --check ``` -Use `markdownlint-cli2` 0.23.2. The repository-owned configuration records +Use `markdownlint-cli2` 0.23.3. The repository-owned configuration records deliberate rule choices. The Rust checker selects tracked Markdown plus nonignored new Markdown, disables configuration globs for that invocation, and refuses a different tool version. It also runs `lychee` 0.21.0 offline diff --git a/docs/dependencies/documentation-toolchain.md b/docs/dependencies/documentation-toolchain.md index a7ef8796..1eed565c 100644 --- a/docs/dependencies/documentation-toolchain.md +++ b/docs/dependencies/documentation-toolchain.md @@ -5,7 +5,7 @@ Keep uses three development-only tools to enforce deterministic documentation and GitHub Actions facts: -- `markdownlint-cli2` 0.23.2 validates Markdown structure; +- `markdownlint-cli2` 0.23.3 validates Markdown structure; - `lychee` 0.21.0 validates local links and fragments with network access disabled; - `actionlint` 1.7.12 validates GitHub Actions syntax and expressions. @@ -20,8 +20,7 @@ The CI job pins Node.js 24.18.0 and installs exact tool releases. The committed `scripts/documentation-tools/package-lock.json` pins every Markdownlint transitive archive and Subresource Integrity digest. The installer uses `npm ci` with lifecycle scripts disabled and refuses lockfile drift. -`markdownlint-cli2` 0.23.2 directly admits the patched `js-yaml` 5.2.2 -release. +`markdownlint-cli2` 0.23.3 admits `js-yaml` 5.4.1, `smol-toml` 1.8.0 and `markdown-it` 15.0.1, addressing the corresponding previously reported parser advisories. The lock graph retains `braces` 3.0.3; [GHSA-vfj7-8cjw-p6xm](https://github.com/advisories/GHSA-vfj7-8cjw-p6xm) has no patched version listed as of 2026-10-03. Follow-up [#176](https://github.com/flyingrobots/keep/issues/176) tracks its disposition; this development-tool update does not claim a clean npm audit. The production documentation command supplies explicit Git-selected paths with `--no-globs`; its bounded runner reports tool failure rather than admitting failed validation. `scripts/install_documentation_tools.sh` verifies the native release archives before extraction: diff --git a/docs/dependencies/yaml-rust2-0.11.0.md b/docs/dependencies/yaml-rust2-0.11.0.md deleted file mode 100644 index e189066d..00000000 --- a/docs/dependencies/yaml-rust2-0.11.0.md +++ /dev/null @@ -1,68 +0,0 @@ -# Dependency Admission: yaml-rust2 0.11.0 - -- Status: Accepted for repository-task workflow admission only -- Date: 2026-07-28 -- Owner: Keep repository verification -- Upstream: - [Ethiraric/yaml-rust2](https://github.com/Ethiraric/yaml-rust2) - -## Admitted use - -Keep admits exactly pinned `yaml-rust2` 0.11.0 only behind the `xtask` crate's -`repository-tasks` feature. The documentation-integrity task parses -`.github/workflows/ci.yml`, selects the `documentation` job's actual `run` -fields, and admits only the reviewed command set. Comments, display strings, -unrelated fields, and additional shell commands cannot satisfy that execution -contract. - -The dependency is absent from Keep's published library graph, public API, -content identities, durable formats, and production behavior. Its typed parse -error remains inside the private repository-task adapter. - -## Why a dependency is needed - -YAML includes quoted and block scalars, comments, aliases, nested collections, -and duplicate mapping keys. A substring scan cannot distinguish executable -`run` fields from inert text. A maintained parser keeps the workflow boundary -structural and fail-closed without creating a partial YAML implementation -inside Keep. - -The parsed values are never hashed, persisted, or admitted as Keep domain -types. The task reads the fixed workflow path through the bounded, -capability-relative, no-follow repository-file boundary before parsing it. - -## Features and resolved graph - -The direct dependency disables default features and is optional. It is -activated solely by `repository-tasks`; disabling defaults excludes the -optional non-UTF-8 input support. - -The introduced normal dependency graph is: - -- `arraydeque` 0.5.1; -- `foldhash` 0.2.0; -- `hashbrown` 0.16.1; and -- `hashlink` 0.11.1. - -## Safety, licensing, and compatibility - -`yaml-rust2` declares the MIT OR Apache-2.0 license expression and a minimum -supported Rust version of 1.65, below Keep's pinned toolchain. Its 0.11.0 Rust -source contains no `unsafe` block. Keep-owned code invokes only safe APIs. - -`cargo deny check licenses bans sources` and `cargo audit` pass with the -resolved graph. These checks remain mandatory point-in-time evidence. - -## Failure and recovery boundaries - -Malformed YAML, duplicate mapping keys, an absent documentation job, an -unreviewed command, an oversized workflow, a non-UTF-8 workflow, or a replaced -repository root produces a typed refusal. The task never repairs, rewrites, or -substitutes workflow data. Parsing has no durability or recovery semantics. - -Keep can remove this dependency without changing public or durable behavior by -replacing it with an equally bounded parser that preserves structural `run` -selection, duplicate-key refusal, and the reviewed-command laws. - -Reopen this admission if the direct version, selected features, resolved graph, -license, MSRV, repository-task-only boundary, or admitted YAML use changes. diff --git a/docs/dependencies/yaml-rust2-0.13.0.md b/docs/dependencies/yaml-rust2-0.13.0.md new file mode 100644 index 00000000..ac90a4df --- /dev/null +++ b/docs/dependencies/yaml-rust2-0.13.0.md @@ -0,0 +1,51 @@ +# Dependency Admission: yaml-rust2 0.13.0 + +- Status: Accepted for repository-task YAML admission only +- Updated: 2026-10-03 +- Owner: Keep repository verification +- Upstream: [Ethiraric/yaml-rust2](https://github.com/Ethiraric/yaml-rust2) + +## Admitted use + +Keep admits exactly pinned `yaml-rust2` 0.13.0 only behind the `xtask` crate's `repository-tasks` feature. The documentation-integrity task parses the CI workflow and Dependabot configuration through `YamlLoader::load_from_str`; fuzz-campaign workflow tests also consume that parser. + +Workflow admission selects the documentation job's actual executable fields and admits only the reviewed steps, permissions, triggers and tool setup. Dependabot admission checks update scopes against the repository's tracked manifests. Comments, display strings and unrelated fields cannot substitute for those structural contracts. + +The dependency is absent from Keep's published library graph, public API, content identities, durable formats and production storage behavior. Its typed parse error remains inside the private repository-task adapter. + +## Why a dependency is needed + +YAML includes quoted and block scalars, comments, aliases, nested collections and duplicate mapping keys. A maintained parser keeps admission structural without introducing a partial YAML implementation inside Keep. + +Parsed values are never hashed, persisted or admitted as Keep domain types. The task reads fixed policy paths through the bounded, capability-relative, no-follow repository-file boundary before parsing. + +## Features and resolved graph + +The direct dependency disables default features and is optional. Only `repository-tasks` activates it; non-UTF-8 decoding through the upstream `encoding` feature is excluded. + +The resolved normal dependency graph includes: + +- `arraydeque` 0.5.1; +- `foldhash` 0.2.0; +- `hashbrown` 0.17.1; and +- `hashlink` 0.12.2. + +## Upgrade and compatibility + +PR #103 updates the previous 0.11.0 admission. Upstream raises its minimum supported Rust version to 1.85.0, below Keep's pinned 1.96.0, and updates hashlink and hashbrown. The MIT OR Apache-2.0 license expression is unchanged. + +The published 0.13.0 source changes its active scanner's `map_or(false, ...)` expression to `is_some_and(...)` and corrects the `Marker::index` documentation to bytes. Its short-input decoder progress fix is inside the disabled `encoding` module; Keep does not claim that fix as an exercised runtime improvement. + +The 0.13.0 Rust source contains no `unsafe` block. Keep-owned code continues to invoke safe APIs, and dependency-owned YAML types remain private to tooling. + +Existing workflow, duplicate-key, Dependabot and CLI admission laws are exercised in debug and release, without editing their expectations. These are bounded tool-contract checks; they do not establish equivalence over every possible YAML input or strengthen Keep's storage claims. + +The reviewed lockfile, license/source policy checks and security advisory checks remain required point-in-time admission evidence. Earlier green checks on 0.11.0 do not certify this graph. + +## Failure and recovery boundaries + +Malformed YAML, duplicate mapping keys, missing policy fields, unreviewed commands, oversized input, non-UTF-8 input and replaced repository roots remain typed refusal cases covered by the existing admission contracts. The task does not repair or rewrite workflow data. Parsing has no storage durability or recovery semantics. + +Keep can remove this dependency without changing public or durable behavior by replacing it with a parser that preserves structural selection, duplicate-key refusal, the reviewed-command laws and the manifest-coverage contract. + +Reopen this admission if the direct version, selected features, resolved graph, license, MSRV, repository-task-only boundary or admitted YAML use changes. diff --git a/scripts/documentation-tools/package-lock.json b/scripts/documentation-tools/package-lock.json index dd742d24..3d59c33d 100644 --- a/scripts/documentation-tools/package-lock.json +++ b/scripts/documentation-tools/package-lock.json @@ -6,7 +6,7 @@ "": { "name": "keep-documentation-tools", "dependencies": { - "markdownlint-cli2": "0.23.2" + "markdownlint-cli2": "0.23.3" } }, "node_modules/@nodelib/fs.scandir": { @@ -205,12 +205,12 @@ } }, "node_modules/entities": { - "version": "4.5.0", - "resolved": "https://registry.npmjs.org/entities/-/entities-4.5.0.tgz", - "integrity": "sha512-V0hjH4dGPh9Ao5p0MoRY6BVqtwCjhz6vI5LT8AJ55H+4g9/4vbHx1I54fS0XuclLhDHArPQCiMjDxjaL8fPxhw==", + "version": "8.1.0", + "resolved": "https://registry.npmjs.org/entities/-/entities-8.1.0.tgz", + "integrity": "sha512-kxL7msIffSuh9aaFAMD7rxAIuTRMAHMeBtgHW2yUdWw732ZNh4MehkF2gdjvtdmikkaIP9bFDDJOPlsvm7avrA==", "license": "BSD-2-Clause", "engines": { - "node": ">=0.12" + "node": ">=20.19.0" }, "funding": { "url": "https://github.com/fb55/entities?sponsor=1" @@ -233,9 +233,9 @@ } }, "node_modules/fastq": { - "version": "1.20.1", - "resolved": "https://registry.npmjs.org/fastq/-/fastq-1.20.1.tgz", - "integrity": "sha512-GGToxJ/w1x32s/D2EKND7kTil4n8OVk/9mycTc4VDza13lOvpUZTGX3mFSCtV9ksdGBVzvsyAVLM6mHFThxXxw==", + "version": "1.20.3", + "resolved": "https://registry.npmjs.org/fastq/-/fastq-1.20.3.tgz", + "integrity": "sha512-XKv5nnLs6nLF71NgiKJLIZFLkPyIEuOselLG7ujZnGrRfQK8HpvY+WqKhAJUAdLomwVHErVS4LfxFlPq0/FTAw==", "license": "ISC", "dependencies": { "reusify": "^1.0.4" @@ -278,15 +278,16 @@ } }, "node_modules/globby": { - "version": "16.2.2", - "resolved": "https://registry.npmjs.org/globby/-/globby-16.2.2.tgz", - "integrity": "sha512-NLvV9ubZ6NDsJaOpKPy3cQeJpKi9DcWiyCiFUpJPA0YihRqiE6RWaLUmgNNPr8MgPpLZjnBjSmou7uZBRJv9wA==", + "version": "16.2.4", + "resolved": "https://registry.npmjs.org/globby/-/globby-16.2.4.tgz", + "integrity": "sha512-c8B/VNLmxRcmqqenRA9t+9IyOjf9+V6lTxPaUJLqOCONdQkWZ0ETYgX0qbtJqPsgCNusT9MZ5Jeidw8Eb9tn2g==", "license": "MIT", "dependencies": { "@sindresorhus/merge-streams": "^4.0.0", "fast-glob": "^3.3.3", "ignore": "^7.0.5", "is-path-inside": "^4.0.0", + "micromatch": "^4.0.8", "slash": "^5.1.0", "unicorn-magic": "^0.4.0" }, @@ -298,9 +299,9 @@ } }, "node_modules/ignore": { - "version": "7.0.6", - "resolved": "https://registry.npmjs.org/ignore/-/ignore-7.0.6.tgz", - "integrity": "sha512-BAg6QkE8W+TuQLrrw0Ugr7HegXduRuuj8/ti2kSOc+jz1dmx8/WNcjr6XGnq5YpDWxFwwaavqD0+jIUOKelTsw==", + "version": "7.0.10", + "resolved": "https://registry.npmjs.org/ignore/-/ignore-7.0.10.tgz", + "integrity": "sha512-HpbUakT7xp5miBUywCHf36ZEuAJNklBJDDsGpUIjMzOSmM8ELSfA9Sa/QDPeNeqeoN31u+UTCkL4klCOVvRm4Q==", "license": "MIT", "engines": { "node": ">= 4" @@ -393,9 +394,9 @@ } }, "node_modules/js-yaml": { - "version": "5.2.2", - "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-5.2.2.tgz", - "integrity": "sha512-dayzUzKkJ1MkuUtZglSebU43utNXH0OWQByK9rKOOuYIO8M5TV1y+n8ALMdG0rdzBnfNkOmZEqrURepb0ejqBw==", + "version": "5.4.1", + "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-5.4.1.tgz", + "integrity": "sha512-28R/k+NAjeuf7+CKlTxWZVExJGwVVLwY06DgEnOMz2gEpfNkDcD7QvyiVPT0xy0XXhU8vHsd4Ot42OOPdJG7dQ==", "funding": [ { "type": "github", @@ -446,9 +447,9 @@ } }, "node_modules/linkify-it": { - "version": "5.0.2", - "resolved": "https://registry.npmjs.org/linkify-it/-/linkify-it-5.0.2.tgz", - "integrity": "sha512-ONTm2jCMAVZjgQa/Fy1kScXsuOoF5NPTsoFBdE1KVIZ2vAh/r9+Bqo+0jINCBYnavTPQZz38QzFTme79ENoN3Q==", + "version": "6.1.0", + "resolved": "https://registry.npmjs.org/linkify-it/-/linkify-it-6.1.0.tgz", + "integrity": "sha512-wJ/TwpSDTLepCrQoYWYIExIKg5Zchex2Nn5yk2mFnB+6PtdkHtyLx742md9csRjjOnGkKIS/RrbY7l8D6gT9Vw==", "funding": [ { "type": "github", @@ -461,13 +462,13 @@ ], "license": "MIT", "dependencies": { - "uc.micro": "^2.0.0" + "uc.micro": "^3.0.0" } }, "node_modules/markdown-it": { - "version": "14.3.0", - "resolved": "https://registry.npmjs.org/markdown-it/-/markdown-it-14.3.0.tgz", - "integrity": "sha512-RCEsPjR+sr0x+AuYp601tKTkgFG4YEPLCzHST3cQ/fhlJkqAkz1L2/Qbp1j9qw5SBwQHFBoW8+hoN5xssOF0Tw==", + "version": "15.0.1", + "resolved": "https://registry.npmjs.org/markdown-it/-/markdown-it-15.0.1.tgz", + "integrity": "sha512-9/7gE95FNPkfUWrjJIoHZza2iLmuJlPD0UNMxPi7bxUrbCR525YZY0r+zyfes0dZI5ZZ/uNIXUJca0pJvtw41g==", "funding": [ { "type": "github", @@ -480,17 +481,33 @@ ], "license": "MIT", "dependencies": { - "argparse": "^2.0.1", - "entities": "^4.5.0", - "linkify-it": "^5.0.2", - "mdurl": "^2.0.0", + "argparse": "^3.0.0", + "entities": "^8.0.0", + "linkify-it": "^6.0.0", + "mdurl": "^2.1.0", "punycode.js": "^2.3.1", - "uc.micro": "^2.1.0" + "uc.micro": "^3.0.0" }, "bin": { "markdown-it": "bin/markdown-it.mjs" } }, + "node_modules/markdown-it/node_modules/argparse": { + "version": "3.0.2", + "resolved": "https://registry.npmjs.org/argparse/-/argparse-3.0.2.tgz", + "integrity": "sha512-mFdDM6WqWKraGLsVb+C9CahPnzTXOefAOLq3jYcca2YZ8bEWpr++Tzj+zSaKW9+X9L5uSxcm1AZ3Y6aZJ09OhQ==", + "funding": [ + { + "type": "github", + "url": "https://github.com/sponsors/puzrin" + }, + { + "type": "github", + "url": "https://github.com/sponsors/nodeca" + } + ], + "license": "PSF-2.0" + }, "node_modules/markdownlint": { "version": "0.41.1", "resolved": "https://registry.npmjs.org/markdownlint/-/markdownlint-0.41.1.tgz", @@ -515,20 +532,20 @@ } }, "node_modules/markdownlint-cli2": { - "version": "0.23.2", - "resolved": "https://registry.npmjs.org/markdownlint-cli2/-/markdownlint-cli2-0.23.2.tgz", - "integrity": "sha512-eUhcnkSpzURo/o4htSqc7LPDszgOOTknhU4eY/sPHvMCLxnTCYscv1gw1/js/idmaZPisv9ECVEIORcllqjTUw==", + "version": "0.23.3", + "resolved": "https://registry.npmjs.org/markdownlint-cli2/-/markdownlint-cli2-0.23.3.tgz", + "integrity": "sha512-xAr5o/TGpC3v6lE6cKIW4b5eOFRrRX5u7Vtjae9ix3RALv8nNOd94XMkD/1OXXBtpMcJ4uQGbpSo3hv5UqS4uQ==", "license": "MIT", "dependencies": { - "globby": "16.2.2", - "js-yaml": "5.2.2", + "globby": "16.2.4", + "js-yaml": "5.4.1", "jsonc-parser": "3.3.1", "jsonpointer": "5.0.1", - "markdown-it": "14.3.0", + "markdown-it": "15.0.1", "markdownlint": "0.41.1", "markdownlint-cli2-formatter-default": "0.0.6", "micromatch": "4.0.8", - "smol-toml": "1.7.0" + "smol-toml": "1.8.0" }, "bin": { "markdownlint-cli2": "markdownlint-cli2-bin.mjs" @@ -1203,9 +1220,9 @@ } }, "node_modules/smol-toml": { - "version": "1.7.0", - "resolved": "https://registry.npmjs.org/smol-toml/-/smol-toml-1.7.0.tgz", - "integrity": "sha512-aqVvWoyO21L23mb+drl4RmMXbf6N7FdHjAhTRA9ZBL7apWBgfWC16KjrASI+1p9GAroljyMHj6fK67i0UiTNvQ==", + "version": "1.8.0", + "resolved": "https://registry.npmjs.org/smol-toml/-/smol-toml-1.8.0.tgz", + "integrity": "sha512-kCZr2V3ch9i00x8zXRhjUNVcjG9ijES5dDudkXvUVCT5QlJNQWElSJdZqyPemffHoLNUYwOcou0Fy+ojN0uHSQ==", "license": "BSD-3-Clause", "engines": { "node": ">= 18" @@ -1258,15 +1275,15 @@ } }, "node_modules/uc.micro": { - "version": "2.1.0", - "resolved": "https://registry.npmjs.org/uc.micro/-/uc.micro-2.1.0.tgz", - "integrity": "sha512-ARDJmphmdvUk6Glw7y9DQ2bFkKBHwQHLi2lsaH6PPmz/Ka9sFOBsBluozhDltWmnv9u/cF6Rt87znRTPV+yp/A==", + "version": "3.0.0", + "resolved": "https://registry.npmjs.org/uc.micro/-/uc.micro-3.0.0.tgz", + "integrity": "sha512-U3PppEkleoTnIfi8BozMx3yju3qc/L6SwqWo2Sw+54PX+PX0q9I+r1Um5HCmqD7n9VDX5/v3vQH/AjA6deDdtw==", "license": "MIT" }, "node_modules/unicorn-magic": { - "version": "0.4.0", - "resolved": "https://registry.npmjs.org/unicorn-magic/-/unicorn-magic-0.4.0.tgz", - "integrity": "sha512-wH590V9VNgYH9g3lH9wWjTrUoKsjLF6sGLjhR4sH1LWpLmCOH0Zf7PukhDA8BiS7KHe4oPNkcTHqYkj7SOGUOw==", + "version": "0.4.1", + "resolved": "https://registry.npmjs.org/unicorn-magic/-/unicorn-magic-0.4.1.tgz", + "integrity": "sha512-lzlXPoVB0Uy/FvTaUgX39RbixYiSKoc3JSoSf01+0c2B6FR3qdYIPN7Qjo/AV7n6sqLCk0509cT3LRj1oSZ1+A==", "license": "MIT", "engines": { "node": ">=20" diff --git a/scripts/documentation-tools/package.json b/scripts/documentation-tools/package.json index e7826ac6..ceff782b 100644 --- a/scripts/documentation-tools/package.json +++ b/scripts/documentation-tools/package.json @@ -2,6 +2,6 @@ "name": "keep-documentation-tools", "private": true, "dependencies": { - "markdownlint-cli2": "0.23.2" + "markdownlint-cli2": "0.23.3" } } diff --git a/xtask/Cargo.toml b/xtask/Cargo.toml index 1c32754c..a8251f15 100644 --- a/xtask/Cargo.toml +++ b/xtask/Cargo.toml @@ -45,7 +45,7 @@ serde_json = { version = "=1.0.151", default-features = false, features = ["std" # Safe self-pipe delivery forwards terminal signals to active child groups. signal-hook = { version = "=0.4.4", default-features = false, features = ["iterator"], optional = true } # Pure Rust YAML admission identifies executable GitHub Actions steps. -yaml-rust2 = { version = "=0.11.0", default-features = false, optional = true } +yaml-rust2 = { version = "=0.13.0", default-features = false, optional = true } [[bin]] name = "xtask" diff --git a/xtask/src/documentation_integrity/execution/tests.rs b/xtask/src/documentation_integrity/execution/tests.rs index 3f68f858..04715369 100644 --- a/xtask/src/documentation_integrity/execution/tests.rs +++ b/xtask/src/documentation_integrity/execution/tests.rs @@ -145,7 +145,7 @@ fn unreviewed_version_stops_before_tool_execution() { result, Err(DocumentationError::VersionMismatch { program: "markdownlint-cli2", - expected: "markdownlint-cli2 v0.23.2 (markdownlint v0.41.1)", + expected: "markdownlint-cli2 v0.23.3 (markdownlint v0.41.1)", ref observed, }) if observed == "markdownlint-cli2 v999.0.0" )); diff --git a/xtask/src/documentation_integrity/node_toolchain.rs b/xtask/src/documentation_integrity/node_toolchain.rs index 140a9253..62b8c539 100644 --- a/xtask/src/documentation_integrity/node_toolchain.rs +++ b/xtask/src/documentation_integrity/node_toolchain.rs @@ -15,8 +15,8 @@ const INSTALLER_DIGEST: [u8; 32] = [ 0x8b, 0x35, 0x54, 0xea, 0x2a, 0x90, 0xeb, 0xd4, 0x82, 0xd7, 0x4a, 0x61, 0x1f, 0xf6, 0xd3, 0xfd, ]; const LOCK_DIGEST: [u8; 32] = [ - 0x74, 0x21, 0xce, 0x90, 0xdd, 0x52, 0x33, 0xfe, 0x99, 0x1a, 0x0b, 0x7e, 0xdd, 0xaa, 0xb7, 0x53, - 0x63, 0xf3, 0xad, 0x3b, 0x0f, 0x9e, 0x7d, 0xa2, 0xa4, 0x77, 0x65, 0xf0, 0x9c, 0x1d, 0xcb, 0x3b, + 0x9e, 0x80, 0x9c, 0x6a, 0xe7, 0xef, 0x97, 0xc5, 0xce, 0x95, 0x97, 0xb8, 0xa9, 0xf0, 0x2d, 0x3f, + 0xee, 0xee, 0xf8, 0xba, 0xa2, 0xd4, 0x8a, 0x54, 0x0f, 0xf5, 0x10, 0x5c, 0x84, 0x5f, 0x5d, 0x37, ]; const LOCK_PATH: &str = "scripts/documentation-tools/package-lock.json"; const MANIFEST_PATH: &str = "scripts/documentation-tools/package.json"; @@ -51,13 +51,13 @@ fn admit_manifest(manifest: &Value) -> Result<(), DocumentationError> { .get("dependencies") .and_then(|dependencies| dependencies.get("markdownlint-cli2")) .and_then(Value::as_str); - if observed == Some("0.23.2") { + if observed == Some("0.23.3") { Ok(()) } else { Err(DocumentationError::RepositoryValue { path: MANIFEST_PATH, field: "dependencies.markdownlint-cli2", - expected: "0.23.2", + expected: "0.23.3", observed: observed.map(str::to_owned), }) } @@ -78,28 +78,28 @@ fn admit_lock(lock: &Value) -> Result<(), DocumentationError> { "", &["dependencies", "markdownlint-cli2"], "packages[\"\"].dependencies.markdownlint-cli2", - "0.23.2", + "0.23.3", )?; require_package_value( packages, "node_modules/markdownlint-cli2", &["dependencies", "js-yaml"], "packages[\"node_modules/markdownlint-cli2\"].dependencies.js-yaml", - "5.2.2", + "5.4.1", )?; require_package_value( packages, "node_modules/js-yaml", &["version"], "packages[\"node_modules/js-yaml\"].version", - "5.2.2", + "5.4.1", )?; require_package_value( packages, "node_modules/markdown-it", &["version"], "packages[\"node_modules/markdown-it\"].version", - "14.3.0", + "15.0.1", )?; require_provenance(packages)?; Ok(()) diff --git a/xtask/src/documentation_integrity/node_toolchain/tests.rs b/xtask/src/documentation_integrity/node_toolchain/tests.rs index 1336533e..8e34ce06 100644 --- a/xtask/src/documentation_integrity/node_toolchain/tests.rs +++ b/xtask/src/documentation_integrity/node_toolchain/tests.rs @@ -5,23 +5,23 @@ use crate::repository_file::RepositoryRoot; #[path = "tests/lock_graph.rs"] mod lock_graph; -const MANIFEST: &str = r#"{"dependencies":{"markdownlint-cli2":"0.23.2"}}"#; +const MANIFEST: &str = r#"{"dependencies":{"markdownlint-cli2":"0.23.3"}}"#; const LOCK: &str = r#"{ "lockfileVersion": 3, "packages": { - "": {"dependencies": {"markdownlint-cli2": "0.23.2"}}, + "": {"dependencies": {"markdownlint-cli2": "0.23.3"}}, "node_modules/markdownlint-cli2": { - "dependencies": {"js-yaml": "5.2.2"}, + "dependencies": {"js-yaml": "5.4.1"}, "resolved": "example", "integrity": "example" }, "node_modules/js-yaml": { - "version": "5.2.2", + "version": "5.4.1", "resolved": "example", "integrity": "example" }, "node_modules/markdown-it": { - "version": "14.3.0", + "version": "15.0.1", "resolved": "example", "integrity": "example" } @@ -43,7 +43,7 @@ fn admitted_node_toolchain_is_exact_and_lockfile_installed() { #[test] fn dependency_overrides_are_refused() { - let manifest = r#"{"overrides":{},"dependencies":{"markdownlint-cli2":"0.23.2"}}"#; + let manifest = r#"{"overrides":{},"dependencies":{"markdownlint-cli2":"0.23.3"}}"#; assert!(matches!( super::admit(manifest, LOCK, INSTALLER), Err(super::DocumentationError::RepositoryContract { @@ -61,7 +61,7 @@ fn manifest_dependency_version_drift_is_refused() { Err(super::DocumentationError::RepositoryValue { path: super::MANIFEST_PATH, field: "dependencies.markdownlint-cli2", - expected: "0.23.2", + expected: "0.23.3", observed: Some(ref observed), }) if observed == "999.0.0" )); @@ -71,11 +71,11 @@ fn manifest_dependency_version_drift_is_refused() { fn duplicate_object_members_are_refused_at_every_depth() { let manifest = concat!( r#"{"dependencies":{"markdownlint-cli2":"999.0.0"},"#, - r#""dependencies":{"markdownlint-cli2":"0.23.2"}}"#, + r#""dependencies":{"markdownlint-cli2":"0.23.3"}}"#, ); let lock = LOCK.replacen( - r#""version": "14.3.0","#, - r#""version": "999.0.0", "version": "14.3.0","#, + r#""version": "15.0.1","#, + r#""version": "999.0.0", "version": "15.0.1","#, 1, ); for result in [ @@ -91,14 +91,14 @@ fn duplicate_object_members_are_refused_at_every_depth() { #[test] fn dependency_version_drift_is_refused() { - let lock = LOCK.replacen("\"5.2.2\"", "\"5.2.1\"", 1); + let lock = LOCK.replacen("\"5.4.1\"", "\"5.2.1\"", 1); let error = super::admit(MANIFEST, &lock, INSTALLER); assert!(matches!( &error, Err(super::DocumentationError::RepositoryValue { path: super::LOCK_PATH, field: "packages[\"node_modules/markdownlint-cli2\"].dependencies.js-yaml", - expected: "5.2.2", + expected: "5.4.1", observed: Some(observed), }) if observed == "5.2.1" )); @@ -107,20 +107,20 @@ fn dependency_version_drift_is_refused() { Err(String::from(concat!( "repository file `scripts/documentation-tools/package-lock.json` requires ", "`packages[\"node_modules/markdownlint-cli2\"].dependencies.js-yaml` to be ", - "\"5.2.2\"; observed \"5.2.1\"" + "\"5.4.1\"; observed \"5.2.1\"" ))) ); } #[test] fn missing_dependency_coordinate_is_refused_precisely() { - let lock = LOCK.replacen("\"version\": \"14.3.0\"", "\"missing\": \"14.3.0\"", 1); + let lock = LOCK.replacen("\"version\": \"15.0.1\"", "\"missing\": \"15.0.1\"", 1); assert!(matches!( super::admit(MANIFEST, &lock, INSTALLER), Err(super::DocumentationError::RepositoryValue { path: super::LOCK_PATH, field: "packages[\"node_modules/markdown-it\"].version", - expected: "14.3.0", + expected: "15.0.1", observed: None, }) )); diff --git a/xtask/src/documentation_integrity/tool.rs b/xtask/src/documentation_integrity/tool.rs index 9d40efbf..1ddbf2d0 100644 --- a/xtask/src/documentation_integrity/tool.rs +++ b/xtask/src/documentation_integrity/tool.rs @@ -22,7 +22,7 @@ impl DocumentationTool { match self { Self::Actionlint => "1.7.12", Self::Lychee => "0.21.0", - Self::Markdownlint => "0.23.2", + Self::Markdownlint => "0.23.3", } } @@ -30,7 +30,7 @@ impl DocumentationTool { match self { Self::Actionlint => "1.7.12", Self::Lychee => "lychee 0.21.0", - Self::Markdownlint => "markdownlint-cli2 v0.23.2 (markdownlint v0.41.1)", + Self::Markdownlint => "markdownlint-cli2 v0.23.3 (markdownlint v0.41.1)", } } diff --git a/xtask/tests/cli_contract/documentation_tools.rs b/xtask/tests/cli_contract/documentation_tools.rs index 7cd86953..1870ac8b 100644 --- a/xtask/tests/cli_contract/documentation_tools.rs +++ b/xtask/tests/cli_contract/documentation_tools.rs @@ -36,7 +36,7 @@ impl DocumentationTools { tools.install( "markdownlint-cli2", "--version", - "markdownlint-cli2 v0.23.2 (markdownlint v0.41.1)", + "markdownlint-cli2 v0.23.3 (markdownlint v0.41.1)", )?; tools.install("lychee", "--version", "lychee 0.21.0")?; tools.install("actionlint", "-version", "1.7.12")?;