Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade highlight.js dependency to v10 #14

Open
Romakita opened this issue Nov 19, 2020 · 8 comments
Open

Upgrade highlight.js dependency to v10 #14

Romakita opened this issue Nov 19, 2020 · 8 comments

Comments

@Romakita
Copy link

Hello Team,

This is problem about the latest dependency about highlight.js related here: highlightjs/highlight.js#2877

Is it possible to upgrade you highlight dependencies to v10 please :)

See you
Romain

@joshgoebel
Copy link

At a glance I think this should be pretty straightforward.

@DannyDainton
Copy link

I would love it if you could update this to version 10 of highlight.js.

I'm starting to get folks logging issues on my repo due to this dependency 😢 - If there anything I can do to help please let me know. 🙏🏻

@joshgoebel
Copy link

Unfortunately I don't have time to make PRs for every downstream library but if someone just bumped the dependencies here and then played around a bit that might get them really far. It's always hard to call these things with just a glance but our public API between v9 -> v10 was actually super stable. You could read the Version 10 release notes to see what changed, but for many, many people upgrading was super simple - despite many small breaking changes.

We no longer support IE11 is the big change that might bite some people. (though that wouldn't matter if you were running this on the server-side).

@joshgoebel
Copy link

Wrote a very tiny guide:

highlightjs/highlight.js#2882

@DannyDainton
Copy link

Hey @jonschlinkert / @doowb / @almeidap

Is there any chance that you could take a look at this issue, please? 🙏

@Romakita
Copy link
Author

@joshgoebel @DannyDainton @almeidap
PR => #17

@jimjaeger
Copy link

Hey,
the linked highlightjs 9.x version has a reported security vulnerability https://snyk.io/test/npm/helper-markdown/1.0.0

There are 2 Pull requests that request to bump to v10:
#17
#16

@jonschlinkert @doowb @almeidap Could you help to merge it to address the security risk?

@rvitaliy
Copy link

👋 Hi @jonschlinkert @doowb
I apologise for the inconvenience, unfortunately for now the only way to get the update for this library is to ask you.
Could you find the time to update it?
If you don't have time, can you invite someone (I volunteer) to help maintain the library?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants