Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

drop dependency on katex #15

Open
mk opened this issue Jun 7, 2023 · 1 comment
Open

drop dependency on katex #15

mk opened this issue Jun 7, 2023 · 1 comment

Comments

@mk
Copy link
Member

mk commented Jun 7, 2023

There's a dependency on katex which shows up in Clerk's js bundle.

Screen Shot 2023-06-07 at 17 54 12

Would be nice if we could drop this or make it optional, as Clerk isn't using it for display (but loading it dynamically). I tried dropping it in nextjournal/clerk@0303e73 but that lets SSR fail.

@rainbow-bamboo
Copy link

rainbow-bamboo commented Jan 4, 2025

Update: As of March 2024, there are a 4 reported and patched moderate vulnerabilities in Katex focused on normalizing URLs and escaping filenames. They have been patched as of 0.16.10 , but the jump from the 0.12 version used to the patched version is listed as a breaking change.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants