Skip to content

Update documentation and Nedi diagrams to Mermaid 12 - #3093

Open
ktsaou wants to merge 2 commits into
masterfrom
update-nedi-browser-deps-sow187
Open

ktsaou wants to merge 2 commits into
masterfrom
update-nedi-browser-deps-sow187

Conversation

@ktsaou

@ktsaou ktsaou commented Sep 17, 2026 •

Copy link
Copy Markdown
Member

Summary

Use Mermaid 12.0.0 for both documentation diagrams and Nedi, with the version 12 rendering defaults. Update Nedi Markdown-it to 15.0.2 and Viz.js to 3.30.0, including matching CDN integrity hashes.

Chevrotain pins vulnerable lodash-es 4.17.23. A qualified resolution selects 4.18.1 for the local bundle; README documents the exact-pin exception. The immutable Nedi CDN was inspected separately: the implementations affected by GHSA-r5fr-rjxr-66jc and GHSA-f23m-r3pf-42rh are absent from its source map. The local resolution does not modify CDN bytes.

Validation

  • Frozen Yarn installation and production build passed.
  • Supported Node 22: 478 Vitest tests passed, one skipped; 73 Node tests passed.
  • Built Registry and Parents pages rendered six diagrams across light/dark modes without browser exceptions.
  • Baseline/candidate audits have identical 168 advisory/path pairs; no introduced findings and no Mermaid/lodash-es findings.
  • Old/new Nedi producer and consumer combinations passed browser rendering checks.

The Viz.js update overlaps #3073. This PR includes that asset change but does not change the other PR's status.


Summary by cubic

Updates documentation and Nedi diagrams to Mermaid 12.0.0 with its new rendering defaults, and bumps Nedi's markdown-it to 15.0.2 and @viz-js/viz to 3.31.0, including matching CDN integrity hashes.

Adds a root resolution for lodash-es 4.18.1 to address a vulnerability in Chevrotain (pinned by Mermaid) that affects only the local documentation bundle; the immutable Nedi CDN assets remain unaffected.

Written for commit cd07f3b. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Bug Fixes
    • Updated the bundled diagram renderer and its parser dependency to address a vulnerable dependency.
  • New Features
    • Updated the separately hosted rendering assets, including Mermaid, Markdown, and graph visualization libraries.

@netlify

netlify Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for netdata-docusaurus ready!

Name Link
🔨 Latest commit cd07f3b
🔍 Latest deploy log https://app.netlify.com/projects/netdata-docusaurus/deploys/6abd8d424efbe00008ec21e2
😎 Deploy Preview https://deploy-preview-3093--netdata-docusaurus.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@coderabbitai

coderabbitai Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 1eddf990-f5d4-4271-8028-50a764522461

📥 Commits

Reviewing files that changed from the base of the PR and between cca14be and cd07f3b.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (4)
  • README.md
  • package.json
  • src/components/Nedi/assets.js
  • tests/dependency_authority.test.js

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The root Mermaid dependency is updated to version 12, and the root Yarn resolution pins lodash-es to 4.18.1. Nedi’s pinned CDN asset versions and integrity hashes are also updated.

Changes

Dependency updates

Layer / File(s) Summary
Root dependencies and resolution
package.json, README.md, tests/dependency_authority.test.js
The Mermaid dependency range changes to ^12.0.0. A Yarn resolution pins lodash-es to 4.18.1. The README documents the resolution exception, and the test expects the new pin.
Nedi CDN asset versions
src/components/Nedi/assets.js
The pinned markdown-it, Mermaid, and @viz-js/viz versions and their integrity hashes are updated.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to cd07f

The dependency and CDN updates have no established merge-blocking issue. Compatibility with the oldest production browsers remains unverified.

Security Architecture Review

Security architecture risk: 🔵 Low · up to cd07f

The update retains fixed CDN versions and integrity controls without a demonstrated expansion of browser authority. No introduced security issue was established, but external rendering implementations and their behavior during partial loading could not be fully verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The relevant exposure is browser-side documentation rendering and the Nedi page’s execution context. The inspected changes do not establish new tenant, server-credential, infrastructure, or agent privileges; external renderer behavior remains outside the verified source scope.

Trust Boundaries and Controls

  • observed — Changed script URLs remain fixed rather than derived from user input. Integrity attributes are propagated to both server/client declarations, and dynamic scripts remain non-async. These controls constrain script identity but do not establish sanitization of attacker-influenced content inside the external embed.

Resilience and Maintainability Implications

  • observed — The existing loader guards repeated requests, tracks injected elements, and removes loader-owned elements before forced retry. Component polling has timeout and interruption cleanup, and failed embed construction removes its provisional container. Readiness checks AiAgentChatUI and Markdown-it, not Mermaid or Viz, so partial renderer availability can coexist with readiness. No introduced unsafe fallback was established, and removing script elements does not undo executed side effects.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the primary changes: updating documentation and Nedi diagrams to Mermaid 12.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 2…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 5 files

Re-trigger cubic

@ktsaou
ktsaou force-pushed the update-nedi-browser-deps-sow187 branch from e95c436 to cd07f3b Compare September 30, 2026 22:29

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant