-
-
Notifications
You must be signed in to change notification settings - Fork 9.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Security] Vulnerability of Low severity in "@storybook/addon-info > marksy > marked" #7842
Comments
|
Pointing to a beta release is not really an appropriate resolution for a security issue. Can we just get an updated 5.1.x release with remediated dependencies? |
@ZebraFlesh PRs welcome |
I dug into this a bit and found the following:
This leads me to believe that the renderers that marksy supplies to marked are bad, but I lack project familiarity to determine what the problem is. |
Hi everyone! Seems like there hasn't been much going on in this issue lately. If there are still questions, comments, or bugs, please feel free to continue the discussion. Unfortunately, we don't have time to get to every issue. We are always open to contributions so please send us a pull request if you would like to help. Inactive issues will be closed after 30 days. Thanks! |
Heyo, this is still present in |
Hi everyone! Seems like there hasn't been much going on in this issue lately. If there are still questions, comments, or bugs, please feel free to continue the discussion. Unfortunately, we don't have time to get to every issue. We are always open to contributions so please send us a pull request if you would like to help. Inactive issues will be closed after 30 days. Thanks! |
Fix please |
If anybody wants to issue a PR for a fix, I'm happy to get it merged. In the meantime, |
Hi everyone! Seems like there hasn't been much going on in this issue lately. If there are still questions, comments, or bugs, please feel free to continue the discussion. Unfortunately, we don't have time to get to every issue. We are always open to contributions so please send us a pull request if you would like to help. Inactive issues will be closed after 30 days. Thanks! |
Related: storybookjs/marksy#78 |
Jiminy cricket!! I just released https://github.com/storybookjs/storybook/releases/tag/v5.3.0-rc.3 containing PR #9234 that references this issue. Upgrade today to try it out! You can find this prerelease on the Closing this issue. Please re-open if you think there's still more to do. |
Hi @shilman, I'm facing the same issue in
|
@gohyifan #7842 (comment) |
Describe the bug
New vulnerability discovered in July in a sub dependency:
@storybook/addon-info > marksy > marked
This is in version
5.1.11
of@storybook/addon-info
.https://www.npmjs.com/advisories/1076
Screenshots
System
The text was updated successfully, but these errors were encountered: