[Snyk] Security upgrade marked from 1.2.9 to 4.0.10 by snyk-bot ยท Pull Request #1724 ยท docsifyjs/docsify
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
- package-lock.json
Vulnerabilities that will be fixed
With an upgrade:
| Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
|---|---|---|---|---|
| 658/1000 Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.3 |
Regular Expression Denial of Service (ReDoS) SNYK-JS-MARKED-2342073 |
Yes | Proof of Concept | |
| 658/1000 Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.3 |
Regular Expression Denial of Service (ReDoS) SNYK-JS-MARKED-2342082 |
Yes | Proof of Concept |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: marked
The new version differs by 250 commits.- ae01170 chore(release): 4.0.10 [skip ci]
- fceda57 ๐๏ธ build [skip ci]
- 8f80657 fix(security): fix redos vulnerabilities
- c4a3ccd Merge pull request from GHSA-rrrm-qjm4-v8hf
- d7212a6 chore(deps-dev): Bump jasmine from 4.0.0 to 4.0.1 (chore: bump rollup from 3.29.4 to 4.9.2 #2352)
- 5a84db5 chore(deps-dev): Bump rollup from 2.62.0 to 2.63.0 (chore: bump actions/upload-artifact from 3 to 4 #2350)
- 2bc67a5 chore(deps-dev): Bump markdown-it from 12.3.0 to 12.3.2 (chore: bump marked from 4.3.0 to 11.1.1 #2351)
- 98996b8 chore(deps-dev): Bump @ babel/preset-env from 7.16.5 to 7.16.7 (chore: bump eslint-config-prettier from 8.10.0 to 9.1.0 #2353)
- ebc2c95 chore(deps-dev): Bump highlight.js from 11.3.1 to 11.4.0 (chore: bump browser-sync from 2.29.3 to 3.0.2 #2354)
- e5171a9 chore(release): 4.0.9 [skip ci]
- 41990a5 ๐๏ธ build [skip ci]
- a9696e2 fix: retain line breaks in tokens properly (How can I change the font used in codeblocks? #2341)
- 6aacd13 chore(deps-dev): Bump jasmine from 3.10.0 to 4.0.0 (chore: bump marked from 4.3.0 to 11.1.0 #2343)
- 55e5df9 chore(deps-dev): Bump @ babel/core from 7.16.5 to 7.16.7 (Update logo doc #2344)
- 4f4cab4 chore(deps-dev): Bump eslint-plugin-import from 2.25.3 to 2.25.4 (Import error #2345)
- 97ea9f2 chore(deps-dev): Bump eslint from 8.5.0 to 8.6.0 (Does docsify supports Vue3 global properties? #2346)
- 4c3b853 chore(deps-dev): Bump rollup-plugin-license from 2.6.0 to 2.6.1 (docs: Update logo doc #2347)
- 9396896 chore(deps-dev): Bump rollup from 2.61.1 to 2.62.0 (chore: optimize compressed css script #2338)
- 103a56c chore(deps-dev): Bump @ babel/preset-env from 7.16.4 to 7.16.5 ([Proposal] Refinement project and Preview/Pages support. #2333)
- be771c9 chore(deps-dev): Bump eslint from 8.4.1 to 8.5.0 (search box num error / plugin 'full text search' #2334)
- 67d5a65 chore(deps-dev): Bump @ babel/core from 7.16.0 to 7.16.5 (fix: missing themes for root #2335)
- 991493a chore(deps-dev): Bump eslint-plugin-promise from 5.2.0 to 6.0.0 (All distributable files belong in the same directory (move all to
dist/) #2336) - 59375fb chore(release): 4.0.8 [skip ci]
- 4734c82 ๐๏ธ build [skip ci]
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
๐ง View latest project report