docsifyjs / docsifyjs/docsify-cli

Dependency Marked 1.2.9 npm module is having a high vulnerability open

オープン
#177 コメント 1 件 リアクション 1 件 担当者 0 名 GitHub で見る
主要言語
JavaScript
スター
782
フォーク
166
平均マージ
10時間 49分
マージ済み PR(30日)
1

説明

Dependency module Marked 1.2.9 npm module is having a high vulnerability open.
https://github.com/advisories/GHSA-rrrm-qjm4-v8hf
Marked-1.2.9 is a transient dependency for parent module docsify-cli.
docsify-cli latest version is 4.4.4 which is still using marked-1.2.9 .

Request you move to upgrade dependency module Marked with version > 4.0.10 so that the vulnerability can be fixed and consumers of docsify-cli can use the latest version with no vulnerabilities

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。