docsifyjs / docsifyjs/docsify-cli
Dependency Marked 1.2.9 npm module is having a high vulnerability open
- 主要语言
- JavaScript
- 星标
- 782
- 派生
- 166
- 平均合并
- 10 小时 49 分钟
- 30 天内合并 PR
- 1
描述
Dependency module Marked 1.2.9 npm module is having a high vulnerability open.
https://github.com/advisories/GHSA-rrrm-qjm4-v8hf
Marked-1.2.9 is a transient dependency for parent module docsify-cli.
docsify-cli latest version is 4.4.4 which is still using marked-1.2.9 .
Request you move to upgrade dependency module Marked with version > 4.0.10 so that the vulnerability can be fixed and consumers of docsify-cli can use the latest version with no vulnerabilities
贡献指南
调研方向
Start by inspecting docsify-cli's dependency declaration and how its dependencies are installed or validated. Update the Marked dependency to a version above 4.0.10, then verify that the reported advisory is no longer present and that docsify-cli still works.
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- javascript, nodejs
- 领域
- cli, security
- Issue 类型
- 缺陷
- 难度
- 3/5
- 预计耗时
- 1-2 天
- 活跃度
- 停滞
- 描述清晰度
- 基本清楚
- 新手友好度
- 45/100