Skip to content
This repository was archived by the owner on Jul 23, 2021. It is now read-only.
This repository was archived by the owner on Jul 23, 2021. It is now read-only.

Dependency package "marked" is vulnerable to "Regular Expression Denial of Service" #61

@Methuselah96

Description

@Methuselah96

From @applitopia on Sun, 19 Nov 2017 07:18:17 GMT

What happened

The dev dependency report at https://david-dm.org/facebook/immutable-js?type=dev shows that marked package is vulnerable to "Regular Expression Denial of Service".

Additional information can be found at https://nodesecurity.io/advisories/531 and at markedjs/marked#937.

Even though this type of security issue is probably not a concern on dev dependency it would be nice if we could get rid of it to have a clean report.

How to reproduce

Check the dev dependency report at https://david-dm.org/facebook/immutable-js?type=dev.

Copied from original issue: immutable-js#1448

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions