Skip to content

fix(api): stop README render memory leak (jsdom DOMPurify → sanitize-html) - #14

Merged
NewtTheWolf merged 1 commit into
mainfrom
fix/readme-sanitizer-leak
Sep 22, 2026
Merged

NewtTheWolf merged 1 commit into
mainfrom
fix/readme-sanitizer-leak

Conversation

@NewtTheWolf

Copy link
Copy Markdown
Contributor

Registry pod was OOMKilled every ~25 min since 0.14.1 (124 restarts). Root cause: isomorphic-dompurify on jsdom leaks ~1 MiB per sanitize() under Bun; each 10-min README cache expiry added ~40 MiB.

  • swap isomorphic-dompurify for sanitize-html, same allowlist, shiki inline styles kept
  • new test: XSS cases + memory regression check
  • api version 0.14.2

Verified locally: 490 tests pass, tsc clean, 3000 renders plateau at ~100 MiB.

…EADME render memory leak

isomorphic-dompurify runs on jsdom under Bun and leaks ~1 MiB per
sanitize() call. Every 10-minute README cache expiry re-rendered all
plugins, growing the registry pod by ~40 MiB until the kernel OOM-killed
it at the 512Mi limit (124 restarts in 2 days).

sanitize-html (htmlparser2, no DOM) uses the same tag/attribute allowlist,
keeps shiki inline styles, and plateaus at ~100 MiB over 3000 renders.
Adds a sanitization + memory regression test. Bumps api to 0.14.2.
@vercel

vercel Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
tabularium-docs Ready Ready Preview Sep 22, 2026 6:03pm UTC
tabularium-website Ready Ready Preview Sep 22, 2026 6:03pm UTC

Request Review

@NewtTheWolf
NewtTheWolf merged commit d5d4d19 into main Sep 22, 2026
11 checks passed
@NewtTheWolf
NewtTheWolf deleted the fix/readme-sanitizer-leak branch September 22, 2026 18:04

This branch was successfully deployed

2 active deployments
Preview – tabularium-website — 1bd1c575 Deployed Sep 22, 2026 by vercel[bot]
Preview – tabularium-docs — 1bd1c575 Deployed Sep 22, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant