Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[graphiql] bump markdown-it for SNYK-JS-MARKDOWNIT-6483324 #3574

Closed
1 task done
hubofgitongithub opened this issue Apr 3, 2024 · 1 comment
Closed
1 task done

Comments

@hubofgitongithub
Copy link

Is there an existing issue for this?

  • I have searched the existing issues

Current Behavior

No response

Expected Behavior

No response

Steps To Reproduce

No response

Environment

No response

Anything else?

graphiql is a subdependency of a npm package we are using (@backstage/plugin-api-docs for instance). Our security scanners are triggering on graphiql, as it is using an unsafe version of markdown-it (version 12.x.x). Please bump this package to 13.0.2 or higher, as can be read here: https://security.snyk.io/vuln/SNYK-JS-MARKDOWNIT-6483324

@eMerzh
Copy link
Contributor

eMerzh commented Apr 8, 2024

it seems to have been addressed in #3569 and released already

@acao acao closed this as completed Apr 13, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants