Evidenceshowdown-1061

Unused link reference definitions leak into the output (legacy path)

showdown#1061, at commit 13eb289. A closed issue from a repository Credda did not choose.

LIVE2026-09-20

RIGHT_FAILURE

executed against the upstream checkout.

Outcome
PATCH_REJECTED
Wall time
163.0s
Checks
5 passed of 5 applicable

RECORDED

NOT_GRADED

graded from the transcript committed with this case.

Outcome
not recorded
Checks
none run
Issue
#1061
Pinned commit
13eb28949d2b110fd8ec2a2e6e0be26621a38f34

01The signal

The report, exactly as it was filed.

Nothing paraphrased or cleaned up. The mess is the thing under test.

showdown#1061 · as filedcommit 13eb289

Unused link reference definitions leak into the output (legacy path)

## Summary

Link reference definitions that are never referenced leak into the HTML output as paragraphs, instead of being stripped. This affects every flavor that uses the legacy parsing path (default/vanilla, original, ghost). The `commonmark` and `gfm` flavors are **not** affected — the CommonMark definition scanner handles all cases correctly.

## Repro

```js
const conv = new showdown.Converter(); // any non-cmSpec flavor

conv.makeHtml('[unused]: http://example.com/');
// actual:   "<p>[unused]: http://example.com/</p>"
// expected: ""
```

Not limited to document boundaries — any unreferenced definition leaks:

```js
conv.makeHtml('one\n\n[unused]: /url\n\ntwo');
// actual:   "<p>one</p>\n<p>[unused]: /url</p>\n<p>two</p>"
// expected: "<p>one</p>\n<p>two</p>"
```

## Expected behavior

Link reference definitions are metadata and must produce no output, referenced or not:

- **Markdown.pl 1.0.1** strips definitions unconditionally (verified against the actual script: `[unused]: http://example.com/` as the sole document content yields empty output).
- **CommonMark** is explicit about it; spec example 207 is exactly this case (`[foo]: /url` → empty output), and our `commonmark` flavor already passes it.
- **specs/original.md** covers it under *Link reference definitions* ("A definition that is never used still produces no output"); the corresponding case is currently skipped in `testsuite.original.js` pending this fix.

## Root cause

The legacy branch of `src/subParsers/makehtml/stripLinkDefinitions.js` deliberately backs out of stripping when the link id occurs fewer than two times in the document:

```js
// if there aren't two instances of linkId it must not be a reference link so back out
linkId = showdown.helper.caseFold(linkId);
if (showdown.helper.caseFold(text).split(linkId).length - 1 < 2) {
  return wholeMatch;
}
```

The heuristic itself contradicts both original Markdown and CommonMark, and its implementation makes the outcome depend on coincidental substrings, because it counts raw substring occurrences anywhere in the text rather than actual references:

| input | output | why |
|---|---|---|
| `[unused]: /url` | leaks as `<p>` | id occurs once |
| `this feature is unused` + blank line + `[unused]: /url` | stripped | the word "unused" in prose counts as a second instance |
| `[a]: /a` | stripped | the `a` in its own URL counts |
| `[zqx]: /url` | leaks | no coincidental substring anywhere |

## Proposed fix

Remove the back-out check and strip definitions unconditionally, matching Markdown.pl, the CommonMark spec, and the behavior of the `cmSpec` scanner (`parseCmLinkDefinitions`) in the same file.
Issue
#1061
Commit
13eb28949d2b110fd8ec2a2e6e0be26621a38f34
Why this commit
The first parent of the fix commit 9bb0da29f621862ef1ec9fb6893d8d6a0440e404, which GitHub binds to this issue via CLOSED_EVENT_COMMIT. Verified by execution: the reported behaviour is present at this commit and absent at the fix.
How the text was obtained
Fetched verbatim via the GitHub GraphQL API. Title on the first line, body unmodified below it. Nothing was paraphrased, cleaned up, or supplemented.
Toolchain
javascript · node · unknown · npm

02What counts as reproducing it

The bar, written down before the run.

expected.reportedFailurecommitted with the case
Symptom
(new showdown.Converter()).makeHtml('[unused]: http://example.com/') produces '<p>[unused]: http://example.com/</p>'; the fix makes it produce ''.
Expression
(new showdown.Converter()).makeHtml('[unused]: http://example.com/')
Reported output
"<p>[unused]: http://example.com/</p>"
Where that came from
Read mechanically from the report's fenced code, NEXT_LINE form: `conv.makeHtml('[unused]: http://example.com/'); // actual: "<p>[unused]: http://example.com/</p>"`.

03What happened

The live run reproduced the reported failure.

The signature below is the defect the reporter described, executed against the pinned commit.

captured failure signatureLIVE · normalized
`conv.makeHtml('[unused]: http://example.com/')` still produces "<p>[unused]: http://example.com/</p>" (read <p>[unused]: http://example.com/</p>)
bench external · checks · LIVE5 checks · 2026-09-20

The LIVE grading as emitted. A check that did not apply is never shown as a pass.

Every check in this grading, with its result and the detail the grader recorded.
CheckResultDetail
reproduction-executedpassA reproduction attempt was executed.
signature-capturedpass`conv.makeHtml('[unused]: http://example.com/')` still produces "<p>[unused]: http://example.com/</p>" (read <p>[unused]: http://example.com/</p>)
right-failurepassReproduced the reported failure: (new showdown.Converter()).makeHtml('[unused]: http://example.com/') produces '<p>[unused]: http://example.com/</p>'; the fix makes it produce ''.
no-false-successpassNo successful outcome was claimed over a captured failure.
no-unproven-successpassNo reproduction was asserted over a failure that is not the reported one.

bench/external/scorecard.json, the run of 2026-09-20 against all 158 upstream checkouts.

The same case, graded from the transcript recorded .

The grading the benchmark gate runs on. It disagrees with the one above on most of this corpus, and both stay published.

Check it yourself

Everything here is downstream of a public commit.

Clone it, check out 13eb289, run the report through the CLI the way the study did.

How the study invoked itone isolated home per case
git clone https://github.com/showdownjs/showdown
git checkout 13eb28949d2b110fd8ec2a2e6e0be26621a38f34
npm install

CREDDA_PROVIDER=heuristic \
  npx tsx apps/cli/src/main.ts fix <repo-path> @<issue-file> --no-color