Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security vulnerability in esdoc-publish-html-plugin using [email protected] #85

Open
zachawilson opened this issue Apr 12, 2019 · 0 comments

Comments

@zachawilson
Copy link

Both esdoc and esdoc-publish-html-plugin depend on 'marked', which has a security warning in the npm audit report.

Please upgrade to >=0.6.2 of marked to resolve this audit failure.

See: https://nodesecurity.io/advisories/812 for more information

npm audit --registry https://registry.npmjs.org

                       === npm audit security report ===


                                 Manual Review
             Some vulnerabilities require your attention to resolve

          Visit https://go.npm.me/audit-guide for additional guidance


  Moderate        Regular Expression Denial of Service

  Package         marked

  Patched in      >=0.6.2

  Dependency of   esdoc [dev]

  Path            esdoc > marked

  More info       https://nodesecurity.io/advisories/812


  Moderate        Regular Expression Denial of Service

  Package         marked

  Patched in      >=0.6.2

  Dependency of   esdoc-standard-plugin [dev]

  Path            esdoc-standard-plugin > esdoc-publish-html-plugin > marked

  More info       https://nodesecurity.io/advisories/812

found 2 moderate severity vulnerabilities in 859520 scanned packages
  2 vulnerabilities require manual review. See the full report for details.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant