Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security issue in marksy -> marked #447

Closed
marcysutton opened this issue Jan 4, 2018 · 5 comments
Closed

Security issue in marksy -> marked #447

marcysutton opened this issue Jan 4, 2018 · 5 comments

Comments

@marcysutton
Copy link

I was notified by Github that a repo I made using Spectacle has a moderate security vulnerability coming from the marked package, a dependency of marksy.

Known moderate severity security vulnerability detected in marked < 0.3.9
defined in package-lock.json.package-lock.json update suggested: marked ~> 0.3.9.

I opened an issue against marksy, since they need to do the update: storybookjs/marksy#52

@jbovenschen
Copy link
Contributor

This is resolved now, the marksy package is updated to the latest release of marked, which includes fixes for both vulnerabilities.

@marcysutton
Copy link
Author

Nice, that was quick!

@marcysutton
Copy link
Author

When will this be released?

@kenwheeler
Copy link
Contributor

Today

@kenwheeler
Copy link
Contributor

Fixed in 4.0.5

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants