Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependabot alerts vulnerable PrismJS #310

Open
Tracked by #588
janosh opened this issue Sep 28, 2021 · 0 comments
Open
Tracked by #588

Dependabot alerts vulnerable PrismJS #310

janosh opened this issue Sep 28, 2021 · 0 comments
Labels
assigned Whether or not this bug has been assigned some to some other issues as a subtask or pre-req bug Something isn't working

Comments

@janosh
Copy link
Contributor

janosh commented Sep 28, 2021

GitHub's Dependabot warns about an outdated PrismJS dependency stemming from MDSveX:

Screen Shot 2021-09-28 at 12 05 44

yarn.lock:

mdsvex@^0.9.8:
  version "0.9.8"
  resolved "https://registry.yarnpkg.com/mdsvex/-/mdsvex-0.9.8.tgz#f430988b86c4d9080381de2fbe54326c046487bc"
  integrity sha512-5QvThjRKoKkGH00qdHxLZ5ROd80RgGiJvM2B9opeFreaiGFTLoKKFUgEBCslLrwM24cVGJLmIM3rR83OFDf3tQ==
  dependencies:
    "@types/unist" "^2.0.3"
    prism-svelte "^0.4.7"
    prismjs "^1.17.1"
    vfile-message "^2.0.4"
@pngwn pngwn added bug Something isn't working dependencies labels Oct 3, 2021
@pngwn pngwn modified the milestone: 1.0 Oct 16, 2021
@pngwn pngwn mentioned this issue Feb 24, 2024
13 tasks
@pngwn pngwn added assigned Whether or not this bug has been assigned some to some other issues as a subtask or pre-req and removed dependencies labels Feb 24, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
assigned Whether or not this bug has been assigned some to some other issues as a subtask or pre-req bug Something isn't working
Projects
No open projects
Status: Todo
Development

No branches or pull requests

2 participants