codex-team / codex-team/editor.js

Package security questions

Open
#2,128 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
31.9k
Forks
2.2k
Avg merge
1d 1h
Merged PRs (30d)
1

Description

Really liking the editor so far, but we noticed a few security warnings on socket.dev that we had some questions about:
https://socket.dev/npm/package/@editorjs/editorjs

Wondering if anyone could speak to the issues of [zero width unicode chars](https://socket.dev/npm/issue/zeroWidth) and [uses eval](https://socket.dev/npm/issue/usesEval) that it found and the necessity of those two things within the package.

Thank you!

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.