Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

upgrade markdown-it dependency to ~10.0.0 to fix vulnerability #198

Closed
nabilnaffar-sf opened this issue Jan 5, 2020 · 4 comments · Fixed by #219
Closed

upgrade markdown-it dependency to ~10.0.0 to fix vulnerability #198

nabilnaffar-sf opened this issue Jan 5, 2020 · 4 comments · Fixed by #219

Comments

@nabilnaffar-sf
Copy link

https://app.snyk.io/vuln/SNYK-JS-MARKDOWNIT-459438

@fmvilas
Copy link
Member

fmvilas commented Jan 8, 2020

Agree, we should upgrade it. Do you mind sending a pull request? If you do, please don't include package-lock.json. Thanks!

@nabilnaffar-sf
Copy link
Author

@fmvilas sure, just from curiosity why do you exclude package-lock.json?

@fmvilas
Copy link
Member

fmvilas commented Jan 8, 2020

Good question. I recently learned about this so now I take care of updating package-lock myself.

@derberg
Copy link
Member

derberg commented Feb 17, 2020

This one will be fixed with merge of #219

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants