docsifyjs / docsifyjs/docsify-cli

Dependency Marked 1.2.9 npm module is having a high vulnerability open

未关闭
#177 1 条评论 1 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
JavaScript
星标
782
派生
166
平均合并
10 小时 49 分钟
30 天内合并 PR
1

描述

Dependency module Marked 1.2.9 npm module is having a high vulnerability open.
https://github.com/advisories/GHSA-rrrm-qjm4-v8hf
Marked-1.2.9 is a transient dependency for parent module docsify-cli.
docsify-cli latest version is 4.4.4 which is still using marked-1.2.9 .

Request you move to upgrade dependency module Marked with version > 4.0.10 so that the vulnerability can be fixed and consumers of docsify-cli can use the latest version with no vulnerabilities

贡献指南

打开贡献指南

调研方向

Start by inspecting docsify-cli's dependency declaration and how its dependencies are installed or validated. Update the Marked dependency to a version above 4.0.10, then verify that the reported advisory is no longer present and that docsify-cli still works.

由索引模型根据 Issue 内容生成。

评估

技术栈
javascript, nodejs
领域
cli, security
Issue 类型
缺陷
难度
3/5
预计耗时
1-2 天
活跃度
停滞
描述清晰度
基本清楚
新手友好度
45/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。