Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

GitHub Dependabot cannot update marked to a non-vulnerable version #161

Closed
wkande opened this issue Mar 31, 2021 · 3 comments
Closed

GitHub Dependabot cannot update marked to a non-vulnerable version #161

wkande opened this issue Mar 31, 2021 · 3 comments
Assignees

Comments

@wkande
Copy link

wkande commented Mar 31, 2021

I think that markdown-link-check needs to update its dependency of markdown-link-extractor that in turn will get a newer version of marked?

Anyway it is upsetting GitHub Dependabot.


From GitHub Dependabot

Dependabot cannot update marked to a non-vulnerable version
The latest possible version that can be installed is 1.2.9 because of the following conflicting dependency:

markdown-link-check@3.8.6 requires marked@^1.1.1 via markdown-link-extractor@1.2.6
The earliest fixed version is 2.0.0.

View logs or learn more about troubleshooting Dependabot errors.

@tcort tcort self-assigned this Apr 2, 2021
@tcort
Copy link
Owner

tcort commented Apr 2, 2021

updated in master.

I'll roll a new release soon.

@tcort tcort closed this as completed Apr 2, 2021
@wkande
Copy link
Author

wkande commented Apr 2, 2021

Great! Thanks for the quick update, and thanks for a good product.

@elaine24punto
This comment has been minimized.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants