Skip to content

[Snyk] Security upgrade markdown-it from 8.4.0 to 12.3.2#153

Open
snyk-bot wants to merge 1 commit intoadd-link-docsfrom
snyk-fix-3a040d7d24a7a35ccc048d4f473bcc9e
Open

[Snyk] Security upgrade markdown-it from 8.4.0 to 12.3.2#153
snyk-bot wants to merge 1 commit intoadd-link-docsfrom
snyk-fix-3a040d7d24a7a35ccc048d4f473bcc9e

Conversation

@snyk-bot
Copy link
Copy Markdown

Snyk has created this PR to fix one or more vulnerable packages in the `yarn` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • lib/vscode/extensions/extension-editing/package.json
⚠️ Warning
Failed to update the yarn.lock, please update manually before merging.

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 551/1000
Why? Recently disclosed, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-MARKDOWNIT-2331914
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

@atomist atomist bot added auto-branch-delete:on-close Delete branch when pull request gets closed auto-merge-method:merge Auto-merge with merge commit auto-merge:on-bpr-success Auto-merge on passed branch protection rule labels Jan 10, 2022
Copy link
Copy Markdown

@github-actions github-actions bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Scan Summary

Tool Critical High Medium Low Status
Dependency Scan (nodejs) 1 3 2 2
Shell Script Analysis 0 0 0 0
Security Audit for Infrastructure 0 1 0 10
Secrets Audit 0 5 0 0

Recommendation

Please review the findings from Code scanning alerts before approving this pull request. You can also configure the build rules or add suppressions to customize this bot 👍

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auto-branch-delete:on-close Delete branch when pull request gets closed auto-merge:on-bpr-success Auto-merge on passed branch protection rule auto-merge-method:merge Auto-merge with merge commit security findings

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant