-
Notifications
You must be signed in to change notification settings - Fork 169
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
deps: Update markdown-it
to fix vulnerability warnings
#204
base: master
Are you sure you want to change the base?
Conversation
As shown on iamacup#202 `markdown-it` v10.x.x includes certain vulnerabilities which were fixed on subsequent versions. This updates the dependency to fix these vulnerabilities
@iamacup @miallo @RonRadtke kindly merge so that the Synk Vulnerability can be resolved: |
@iamacup Can we please fix this security vulmn for the community? |
@mthahzan there is an update to the |
Updated `@types/markdown-it` to new version
@david-gettins thanks! PR Updated. Also, I noticed latest version of markdown-it is 14.1.0 now. Didn't have the time to test it out to see if works or not. If someone can verify, I can bump the version of that as well. |
Any plans when this will be merged? |
If like myself you would like a temporary workaround for the audit issues you can use force-resolutions to force the fixed version of Of course, you can always look for an alternative library. If you find one, please let us all know. I would prefer not to use the forced resolution. |
@iamacup ping |
Is there any update on this?? @iamacup |
@javigutierrezfer i use bun and fixed it by setting the patch version in "overrides": { Didn't notice any issues. |
I'm also getting this some upstream issues with markdown-it. Updating this dep might be helpful |
@iamacup ping |
As shown on #202
markdown-it
v10.x.x includes certain vulnerabilities which were fixed on subsequent versions. This updates the dependency to fix these vulnerabilities.