Conversation
|
Please merge! It fixes an exploit. WS-2019-0027 markedjs/marked@b15e42b Vulnerable versions: < 0.3.18 Versions 0.3.17 and earlier of marked has Four regexes were vulnerable to catastrophic backtracking. This leaves markdown servers open to a potential REDOS attack. |
e7d1a86 to
7ab94da
Compare
|
@grant-g @jenschlot Sorry to bother you, but the security alert is 9 months old and I cannot resolve this on my end because it is the dependency of a dependency. |
|
@Simran-B The only reason I'm delaying on this is to compare a before-and-after runs on a set of docs to see the HTML generation changes this would bring with it. I will try to get to this soon. FWIW the potential exploit should not prove to be a problem unless you receive and process source content unchecked from external sources. I believe the patterns in source that would be needed to cause these problems are somewhat specific and unusual. |
7ab94da to
66b26eb
Compare
66b26eb to
bdb3c32
Compare
bdb3c32 to
06b680a
Compare
8c7f185 to
085bcb6
Compare
44ffc28 to
4ec0272
Compare
446b93e to
c2c276c
Compare
e1fc813 to
5f1310b
Compare
5f1310b to
6d8dc53
Compare
1c028e7 to
a2b629f
Compare
76c1bf7 to
fffa4af
Compare
b976565 to
aac3e89
Compare
Bumps [marked](https://github.com/markedjs/marked) from 0.3.9 to 0.3.18. - [Release notes](https://github.com/markedjs/marked/releases) - [Commits](markedjs/marked@0.3.9...v0.3.18) Signed-off-by: dependabot[bot] <support@github.com>
aac3e89 to
edae829
Compare
|
Superseded by #35. |
Bumps marked from 0.3.9 to 0.3.18.
Release notes
Sourced from marked's releases.
Commits
c1e19a9Merge pull request #1152 from 8fold/release-0.3.1898c9d14Update home page5d5fa040.3.186661fe5Merge pull request #1148 from 8fold/styfle-admin5d3d70aMerge pull request #1144 from paulroub/OL_initial_numbers002c565Merge pull request #1151 from wraith13/master2c20df9Fix usage links in USING_ADVANCED.mdf69a82fRemove redundant castf886f40Merge pull request #1147 from 8fold/update-badges78a0258styfle to adminDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot ignore this [patch|minor|major] versionwill close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)@dependabot use these labelswill set the current labels as the default for future PRs for this repo and language@dependabot use these reviewerswill set the current reviewers as the default for future PRs for this repo and language@dependabot use these assigneeswill set the current assignees as the default for future PRs for this repo and language@dependabot use this milestonewill set the current milestone as the default for future PRs for this repo and languageYou can disable automated security fix PRs for this repo from the Security Alerts page.