Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade marked from 0.6.2 to 0.7.0 #1

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to upgrade marked from 0.6.2 to 0.7.0.

  • The recommended version is 2 versions ahead of your current version.
  • The recommended version was released 4 months ago, on 2019-07-06.

The recommended version fixes:

Severity Title Issue ID
Regular Expression Denial of Service (ReDoS) SNYK-JS-MARKED-451341
Release notes
  • Package name: marked
    • 0.7.0 - 2019-07-06

      Security

      • Sanitize paragraph and text tokens #1504
      • Fix ReDOS for links with backticks (issue #1493) #1515

      Breaking Changes

      • Deprecate sanitize and sanitizer options #1504
      • Move fences to CommonMark #1511
      • Move tables to GFM #1511
      • Remove tables option #1511
      • Single backtick in link text needs to be escaped #1515

      Fixes

      Tests

      • Run tests with correct options #1511
    • 0.6.3 - 2019-06-30

      Fixes

      Docs

      • add docs for workers #1432
      • Add security policy #1492
      • Update supported spec versions #1491
      • Update test folder descriptions #1506

      DevOps

      • Use latest commit for demo master #1457
      • Update tests to commonmark 0.29 #1465
      • Update tests to GFM 0.29 #1470
      • Fix commonmark spec 57 and 40 (headings) #1475
    • 0.6.2 - 2019-04-05

      Security

      Fixes

      • Links parens #1435
      • New line after table with escaped pipe #1439
      • List item tables #1446

      Enhancements

      • Pass token boolean to the listitem function #1440
      • Allow html without \n after #1438

      CLI

      • Update man page to include --test and fix argv parameters #1442
      • Add a --version flag to print marked version #1448

      Testing

      • Normalize marked tests #1444
      • Update tests to node 4 syntax #1449
  • from [`marked` GitHub Release Notes](https://github.com/markedjs/marked/releases)
------------

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant