Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: bumps prismjs dependency from 1.22.0 to 1.25.0 #430

Merged

Conversation

rusackas
Copy link
Contributor

@rusackas rusackas commented Oct 13, 2021

Bumps the prismjs dependency to 1.25.0 in order to resolve vulnerabilities in the prismjs package including:

Resolves part of #429
Fixes #415

@rusackas
Copy link
Contributor Author

rusackas commented Oct 13, 2021

I'm a rookie here, but I'm attempting a different approach to bumping this package, as opposed to the dependabot bump. Doing it via the package.json file and running npm install generated a lot of files... I hope this helps.

@rusackas
Copy link
Contributor Author

I'm pretty shocked at the size of the PR... not sure if these files should be gitignored or what. I don't see a contributing.md so I could use a little help if I'm just doing this all wrong ¯\_(ツ)_/¯

@michael-s-molina
Copy link

+1

@rusackas
Copy link
Contributor Author

@conorhastings @simmerer any help/tips here would be appreciated.

@jonathansantilli
Copy link

Hello! who can merge this PR? I have tried upgrading the prismjs dependency in the same way and got the same results as @rusackas

@conorhastings conorhastings merged commit 20d9444 into react-syntax-highlighter:master Nov 12, 2021
@conorhastings
Copy link
Collaborator

Hey @rusackas thanks for the email to draw my attention here published as 15.4.5

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Prismjs vulnerability - level high
4 participants