Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

vulnerable package marked #280

Closed
MaksPob opened this issue Apr 11, 2019 · 0 comments · Fixed by #281
Closed

vulnerable package marked #280

MaksPob opened this issue Apr 11, 2019 · 0 comments · Fixed by #281

Comments

@MaksPob
Copy link

MaksPob commented Apr 11, 2019

You have old version vulnerable package marked
https://app.snyk.io/vuln/SNYK-JS-MARKED-174116
Upgrade package to 0.6.2

petebacondarwin added a commit to petebacondarwin/dgeni-packages that referenced this issue May 6, 2019
The previous version of `marked` was vulnerable to a
[ReDoS](https://app.snyk.io/vuln/SNYK-JS-MARKED-174116)
attack.

BREAKING CHANGES

There are a few relevant breaking changes with this latest version of `marked`.
This only affects usage of the `renderMarkdown()` service and the `marked`
nunjucks filter. Take a look through the
[marked release notes](https://github.com/markedjs/marked/releases) and
check if this affects you.

Fixes angular#280
petebacondarwin added a commit to petebacondarwin/dgeni-packages that referenced this issue Jul 12, 2019
The previous version of `marked` was vulnerable to a
[ReDoS](https://app.snyk.io/vuln/SNYK-JS-MARKED-174116)
attack.

BREAKING CHANGES

There are a few relevant breaking changes with this latest version of `marked`.
This only affects usage of the `renderMarkdown()` service and the `marked`
nunjucks filter. Take a look through the
[marked release notes](https://github.com/markedjs/marked/releases) and
check if this affects you.

Fixes angular#280
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant