docsifyjs / docsifyjs/docsify-cli

Dependency Marked 1.2.9 npm module is having a high vulnerability open

未關閉
#177 1 則留言 1 個 reaction 已指派 0 人 在 GitHub 檢視
主要語言
JavaScript
星號
782
分支
166
平均合併
10 小時 49 分鐘
30 天內合併 PR
1

描述

Dependency module Marked 1.2.9 npm module is having a high vulnerability open.
https://github.com/advisories/GHSA-rrrm-qjm4-v8hf
Marked-1.2.9 is a transient dependency for parent module docsify-cli.
docsify-cli latest version is 4.4.4 which is still using marked-1.2.9 .

Request you move to upgrade dependency module Marked with version > 4.0.10 so that the vulnerability can be fixed and consumers of docsify-cli can use the latest version with no vulnerabilities

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。