Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade mavon-editor from 2.9.0 to 2.10.2 #199

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link
Contributor

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 556/1000
Why? Recently disclosed, Has a fix available, CVSS 5.4
Cross-site Scripting (XSS)
SNYK-JS-MAVONEDITOR-2317043
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: mavon-editor The new version differs by 104 commits.
  • d325c45 Release v2.10.2
  • b9489a3 fix: Add sanitizer for filtering HTML tags (#744)
  • 8a2eb2a Create SECURITY.md
  • 1fb7073 release v2.10.1
  • a7d4376 test: add more xss and image testcase (#739)
  • 9933119 fix: image cannot be previewed (#738)
  • ca87152 Add vue3 version badge
  • 2a6fa04 doc: update markdown.md
  • 4937828 doc: Additional notes (#734)
  • 3ea9622 doc: document style (#646)
  • bf97a96 添加了一个在编辑器外渲染markdown的例子 (#612)
  • 38079d5 Merge pull request #730 from jiawulin001/fix-729
  • 69210e1 Merge pull request #731 from wangsongc/test-2.10.0
  • cd409d9 doc: customize and add toolbar buttons
  • c611bdd fix: Fix the content of code blocks to be displayed outside the pre container,issue #729
  • d29e1bf Merge pull request #728 from jiawulin001/master
  • 720c987 Fix build warnings and optimize console output
  • fcce24d Update README.md
  • 1d571f7 Merge pull request #725 from jiawulin001/master
  • 96d7a08 release v2.10.0
  • b4a6fb7 Merge pull request #726 from wangsongc/test-2.10.0
  • 5f23e0b test: add xss test
  • d7ff5f2 Add switch code style demo and build to add checks
  • 57c3f2a Merge pull request #611 from XLCYun/master

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant