docsifyjs / docsifyjs/docsify-cli

Dependency Marked 1.2.9 npm module is having a high vulnerability open

Open
#177 1 comment 1 reaction 0 assignees View on GitHub
Dominant language
JavaScript
Stars
782
Forks
166
Avg merge
10h 49m
Merged PRs (30d)
1

Description

Dependency module Marked 1.2.9 npm module is having a high vulnerability open.
https://github.com/advisories/GHSA-rrrm-qjm4-v8hf
Marked-1.2.9 is a transient dependency for parent module docsify-cli.
docsify-cli latest version is 4.4.4 which is still using marked-1.2.9 .

Request you move to upgrade dependency module Marked with version > 4.0.10 so that the vulnerability can be fixed and consumers of docsify-cli can use the latest version with no vulnerabilities

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.