Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update prismjs dependency version #389

Closed
rogov-k opened this issue Jun 9, 2022 · 1 comment
Closed

Update prismjs dependency version #389

rogov-k opened this issue Jun 9, 2022 · 1 comment
Labels
dependencies Pull requests that update a dependency file

Comments

@rogov-k
Copy link
Contributor

rogov-k commented Jun 9, 2022

Dear colleagues,

Today ngx-markdown has prismjs@^1.25.0 version. That version has vulnerability (see more issue 1, issue 2 and pull reques). I suggest to update prismjs to ^1.28.0 version. I tried to do it locally and it looks good at first glance.

@jfcere
Copy link
Owner

jfcere commented Jun 9, 2022

Hi @rogov-k,

Thank you for your contribution, your PR has been accepted and will be available in ngx-markdown v14 that will be released early next week alongside the update to Angular 14.

Please note that ngx-markdown version allows prism version 1.28.0 to be used as the dependency is set as ^1.25.0, so in the meanwhile just be sure to update your packages or force the update if you have a package-lock file.

@jfcere jfcere closed this as completed Jun 9, 2022
@jfcere jfcere added the dependencies Pull requests that update a dependency file label Jun 9, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

No branches or pull requests

2 participants