-
-
Notifications
You must be signed in to change notification settings - Fork 5.7k
New release - marked vulnerability alert #2505
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Comments
Hi @noraj , thx for you mention on this. |
hi, any news on this? it will be good to have the updated dependency for marked published asap. |
Planned release in the near future. |
You should just release it now because it makes other popupar repos that add docsify as dependency appear vulnerable when ppl clone them and see the red and yellow warnings, also encourages ppl to remove as dependency to make scaring own users go away, whatever is blocking release for half a year now should just be saved for another one |
It would be nice to have a new release of dosify including the current work.
Indeed, last release is v4.13.1 from Jun 24, 2023. What's annoying is that docsify v4.13.1 was using marked v1.2.9
docsify/package.json
Line 68 in 862b100
So any project using docsify on github right now, have 3 vulnerability alerts opened:
Even if not really vulnerable, that makes tons of projects receiving 3 false positive vulnerability alerts. And since no newer release is available, one can't "path" other than dismissing the alert.
It's already fixed since now docsify uses marked v14.1.0, we just are lacking a newer release.
https://github.com/docsifyjs/docsify/blob/ceb466ca9c29bec775f4ebda449f8ea40a5453df/package.json#L73C6-L73C13
The text was updated successfully, but these errors were encountered: