[Snyk] Security upgrade marked from 1.2.9 to 2.0.0 by sy-records · Pull Request #1505 · docsifyjs/docsify
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
- package-lock.json
Vulnerabilities that will be fixed
With an upgrade:
| Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
|---|---|---|---|---|
| 661/1000 Why? Recently disclosed, Has a fix available, CVSS 7.5 |
Regular Expression Denial of Service (ReDoS) SNYK-JS-MARKED-1070800 |
Yes | No Known Exploit |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: marked
The new version differs by 4 commits.- 8a7502f chore(release): 2.0.0 [skip ci]
- 9d3a781 🗜️ build [skip ci]
- 7293251 fix: Total rework of Emphasis/Strong (#1864)
- f848e77 fix: Join adjacent inlineText tokens (chore: bump minimatch from 3.0.4 to 3.1.2 #1926)
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report