[Snyk] Security upgrade marked from 0.3.5 to 4.0.10
Created by: snyk-bot
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
- package-lock.json
Vulnerabilities that will be fixed
With an upgrade:
Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
---|---|---|---|---|
658/1000 Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.3 |
Regular Expression Denial of Service (ReDoS) SNYK-JS-MARKED-2342073 |
Yes | Proof of Concept | |
658/1000 Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.3 |
Regular Expression Denial of Service (ReDoS) SNYK-JS-MARKED-2342082 |
Yes | Proof of Concept |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: marked
The new version differs by 250 commits.- ae01170 chore(release): 4.0.10 [skip ci]
-
fceda57
🗜 ️ build [skip ci] - 8f80657 fix(security): fix redos vulnerabilities
- c4a3ccd Merge pull request from GHSA-rrrm-qjm4-v8hf
- d7212a6 chore(deps-dev): Bump jasmine from 4.0.0 to 4.0.1 (#2352)
- 5a84db5 chore(deps-dev): Bump rollup from 2.62.0 to 2.63.0 (#2350)
- 2bc67a5 chore(deps-dev): Bump markdown-it from 12.3.0 to 12.3.2 (#2351)
- 98996b8 chore(deps-dev): Bump @ babel/preset-env from 7.16.5 to 7.16.7 (#2353)
- ebc2c95 chore(deps-dev): Bump highlight.js from 11.3.1 to 11.4.0 (#2354)
- e5171a9 chore(release): 4.0.9 [skip ci]
-
41990a5
🗜 ️ build [skip ci] - a9696e2 fix: retain line breaks in tokens properly (#2341)
- 6aacd13 chore(deps-dev): Bump jasmine from 3.10.0 to 4.0.0 (#2343)
- 55e5df9 chore(deps-dev): Bump @ babel/core from 7.16.5 to 7.16.7 (#2344)
- 4f4cab4 chore(deps-dev): Bump eslint-plugin-import from 2.25.3 to 2.25.4 (#2345)
- 97ea9f2 chore(deps-dev): Bump eslint from 8.5.0 to 8.6.0 (#2346)
- 4c3b853 chore(deps-dev): Bump rollup-plugin-license from 2.6.0 to 2.6.1 (#2347)
- 9396896 chore(deps-dev): Bump rollup from 2.61.1 to 2.62.0 (#2338)
- 103a56c chore(deps-dev): Bump @ babel/preset-env from 7.16.4 to 7.16.5 (#2333)
- be771c9 chore(deps-dev): Bump eslint from 8.4.1 to 8.5.0 (#2334)
- 67d5a65 chore(deps-dev): Bump @ babel/core from 7.16.0 to 7.16.5 (#2335)
- 991493a chore(deps-dev): Bump eslint-plugin-promise from 5.2.0 to 6.0.0 (#2336)
- 59375fb chore(release): 4.0.8 [skip ci]
-
4734c82
🗜 ️ build [skip ci]
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information: 🧐 View latest project report