Skip to content

fix: remove unused languine dependency (resolves CVE-2026-41650) - #4226

Merged
Jocs merged 1 commit into
developfrom
fix/remove-unused-languine-dependency
May 16, 2026
Merged

Jocs merged 1 commit into
developfrom
fix/remove-unused-languine-dependency

Conversation

@Jocs

@Jocs Jocs commented May 16, 2026

Copy link
Copy Markdown
Member

Summary

  • Remove languine from dependencies in package.json
  • Update pnpm-lock.yaml accordingly

Background

[email protected] was added to dependencies in the electron-vite refactor (#4001), but it is never actually used:

  • No import/require of languine anywhere in the source code
  • No languine.config.* configuration file exists
  • No reference to languine in any npm scripts

Dependabot alert #409 (GHSA-gh4j-gqv2-49f6 / CVE-2026-41650) flagged the transitive dependency [email protected] (pulled in by languine) for an XML comment/CDATA injection vulnerability in XMLBuilder. The fix version (5.7.0) is a major version jump that languine does not yet consume, so upgrading languine alone would not resolve it.

Since languine is unused, the cleanest fix is to remove it entirely, which also drops fast-xml-parser from the dependency tree.

Test plan

  • pnpm install completes successfully
  • fast-xml-parser and languine no longer appear in pnpm-lock.yaml
  • No source files import or reference languine

🤖 Generated with Claude Code

languine was added to `dependencies` in the electron-vite refactor (#4001)
but is never imported, has no config file, and is not referenced in any
scripts. Removing it eliminates the transitive [email protected]
dependency that triggered Dependabot alert #409 (GHSA-gh4j-gqv2-49f6,
medium severity, XML comment/CDATA injection in XMLBuilder).

Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
Copilot AI review requested due to automatic review settings May 16, 2026 08:32

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR removes the unused languine production dependency to eliminate its vulnerable transitive dependency (fast-xml-parser, CVE-2026-41650) from the dependency tree.

Changes:

  • Removed languine from dependencies in package.json.
  • Updated pnpm-lock.yaml to drop languine and its transitive packages (including fast-xml-parser).

Reviewed changes

Copilot reviewed 1 out of 2 changed files in this pull request and generated no comments.

File Description
package.json Removes the unused languine dependency from production dependencies.
pnpm-lock.yaml Updates the lockfile to remove languine, fast-xml-parser, and now-unneeded transitive entries.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@github-actions

Copy link
Copy Markdown

Build artifacts for PR #4226:

Run: https://github.com/marktext/marktext/actions/runs/25957402453

Artifact Size Link
marktext-macos-x64 535.7 MB Download
marktext-linux 596.0 MB Download
marktext-windows 273.2 MB Download
marktext-macos-arm64 535.4 MB Download

@Jocs
Jocs merged commit a8d431e into develop May 16, 2026
14 checks passed
@Jocs
Jocs deleted the fix/remove-unused-languine-dependency branch May 16, 2026 08:44
thimbleberrysystems pushed a commit to thimbleberrysystems/WordBird that referenced this pull request Jun 21, 2026
…ktext#4226)

languine was added to `dependencies` in the electron-vite refactor (marktext#4001)
but is never imported, has no config file, and is not referenced in any
scripts. Removing it eliminates the transitive [email protected]
dependency that triggered Dependabot alert marktext#409 (GHSA-gh4j-gqv2-49f6,
medium severity, XML comment/CDATA injection in XMLBuilder).

Co-authored-by: Claude Sonnet 4.6 <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants