Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

New release - marked vulnerability alert #2505

Open
noraj opened this issue Oct 20, 2024 · 3 comments
Open

New release - marked vulnerability alert #2505

noraj opened this issue Oct 20, 2024 · 3 comments
Assignees
Labels
attention semver-major This needs a major release

Comments

@noraj
Copy link

noraj commented Oct 20, 2024

It would be nice to have a new release of dosify including the current work.

Indeed, last release is v4.13.1 from Jun 24, 2023. What's annoying is that docsify v4.13.1 was using marked v1.2.9

"marked": "^1.2.9",

So any project using docsify on github right now, have 3 vulnerability alerts opened:

Even if not really vulnerable, that makes tons of projects receiving 3 false positive vulnerability alerts. And since no newer release is available, one can't "path" other than dismissing the alert.

It's already fixed since now docsify uses marked v14.1.0, we just are lacking a newer release.

https://github.com/docsifyjs/docsify/blob/ceb466ca9c29bec775f4ebda449f8ea40a5453df/package.json#L73C6-L73C13

@noraj noraj changed the title New release New release - marked vulnerability alert Oct 20, 2024
@Koooooo-7
Copy link
Member

Hi @noraj , thx for you mention on this.
The new release may take a time to confirm with the members.
I will sync with you when the release decision set done asap.

@asinghal
Copy link

hi, any news on this? it will be good to have the updated dependency for marked published asap.

@sy-records
Copy link
Member

Planned release in the near future.

@sy-records sy-records self-assigned this Feb 26, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
attention semver-major This needs a major release
Projects
None yet
Development

No branches or pull requests

4 participants