Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

marked moderate vulnerability #174

Open
migglu opened this issue Apr 24, 2019 · 3 comments
Open

marked moderate vulnerability #174

migglu opened this issue Apr 24, 2019 · 3 comments

Comments

@migglu
Copy link

migglu commented Apr 24, 2019

There seems to be a vulnerability for the marked dependency here. It can be seen when running npm audit.
The solution seems to be to upgrade to marked v0.6.2 or newer.

@oznu
Copy link

oznu commented Apr 28, 2019

                       === npm audit security report ===                        
                                                                                
┌──────────────────────────────────────────────────────────────────────────────┐
│                                Manual Review                                 │
│            Some vulnerabilities require your attention to resolve            │
│                                                                              │
│         Visit https://go.npm.me/audit-guide for additional guidance          │
└──────────────────────────────────────────────────────────────────────────────┘
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ Moderate      │ Regular Expression Denial of Service                         │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package       │ marked                                                       │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in    │ >=0.6.2                                                      │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ ngx-md                                                       │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path          │ ngx-md > marked                                              │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info     │ https://npmjs.com/advisories/812                             │
└───────────────┴──────────────────────────────────────────────────────────────┘

@xileftenurb
Copy link

will their be a new NPM version with this patch soon?

@dimpu
Copy link
Owner

dimpu commented Dec 20, 2019

@xileftenurb Just pushed it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants