[Snyk] Upgrade marked from 0.3.5 to 0.8.2
Created by: snyk-bot
Snyk has created this PR to upgrade marked from 0.3.5 to 0.8.2.
- The recommended version is 23 versions ahead of your current version.
- The recommended version was released 2 years ago, on 2020-03-22.
The recommended version fixes:
Severity | Issue | PriorityScore (*) | Exploit Maturity |
---|---|---|---|
Regular Expression Denial of Service (ReDoS) npm:marked:20180225 |
696/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 7.5 |
Proof of Concept | |
Regular Expression Denial of Service (ReDoS) npm:marked:20170907 |
696/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 7.5 |
No Known Exploit | |
Cross-site Scripting (XSS) npm:marked:20170815 |
696/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 7.5 |
No Known Exploit | |
Cross-site Scripting (XSS) npm:marked:20170112 |
696/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 7.5 |
No Known Exploit | |
Cross-site Scripting (XSS) npm:marked:20150520 |
696/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 7.5 |
No Known Exploit | |
Cross-site Scripting (XSS) npm:marked:20170815-1 |
696/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 7.5 |
No Known Exploit | |
Regular Expression Denial of Service (ReDoS) SNYK-JS-MARKED-451540 |
696/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 7.5 |
No Known Exploit | |
Regular Expression Denial of Service (ReDoS) SNYK-JS-MARKED-174116 |
696/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 7.5 |
No Known Exploit |
(*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: marked
-
0.8.2 - 2020-03-22
- Update comment about GitHub breaks #1620
-
0.8.1 - 2020-03-18
-
0.8.0 - 2019-12-12
- Fix relative urls in
baseUrl
option #1526 - Loose task list #1535
- Fix image parentheses #1557
- remove module field & update devDependencies #1581
- Update examples with es6+ #1521
- Fix link to USING_PRO.md page #1552
- Fix typo in USING_ADVANCED.md #1558
- Node worker threads are stable #1555
- Fix relative urls in
-
0.7.0 - 2019-07-06
- Deprecate
sanitize
andsanitizer
options #1504 - Move
fences
to CommonMark #1511 - Move
tables
to GFM #1511 - Remove
tables
option #1511 - Single backtick in link text needs to be escaped #1515
- Run tests with correct options #1511
- Deprecate
-
0.6.3 - 2019-06-30
- Fix nested blockquotes #1464
- Fix
<em>
issue with mixed content #1451 - revert #1464 #1497
- Fix
breaks: true
#1507
- add docs for workers #1432
- Add security policy #1492
- Update supported spec versions #1491
- Update test folder descriptions #1506
- 0.6.2 - 2019-04-05 Read more
-
0.6.1 - 2019-02-19
- Fix parenthesis url redos #1414
- 0.6.0 - 2019-01-01 Read more
- 0.5.2 - 2018-11-20 Read more
- 0.5.1 - 2018-09-26 Read more
- 0.5.0 - 2018-08-16
- 0.4.0 - 2018-05-21
- 0.3.19 - 2018-03-26
- 0.3.18 - 2018-03-22
- 0.3.17 - 2018-02-27
- 0.3.16 - 2018-02-20
- 0.3.15 - 2018-02-19
- 0.3.14 - 2018-02-16
- 0.3.13 - 2018-02-16
- 0.3.12 - 2018-01-09
- 0.3.9 - 2017-12-23
- 0.3.7 - 2017-12-01
- 0.3.6 - 2016-07-30
- 0.3.5 - 2015-07-31
Commit messages
Package name: marked
- 4af69d3 Merge pull request #1624 from UziTech/release-0.8.2
- 19f0d4f 0.8.2
- 38403c0 build
- d7b05cb update devdeps
- 17ee15f build [skip ci]
- 58e9fed Merge pull request #1622 from UziTech/render-html
- 193a41e simplify tag regex
- 7330a9c add html test to heading ids
- f01ba94 add html to TextRenderer
- cf3d0a0 Merge pull request #1620 from julien-c/patch-1
- 9f2c0d1 Update docs/USING_ADVANCED.md
- 885d728 Update docs/USING_ADVANCED.md
- b8c5541 Merge pull request #1616 from UziTech/release-0.8.1
- 20d85bd 0.8.1
- b0928cb build [skip ci]
- 8d51037 Merge pull request #1617 from UziTech/following-nptable
- 4e3d20d Remove inaccurate proposition on GitHub
- c71ac10 Merge pull request #1619 from markedjs/dependabot/npm_and_yarn/acorn-7.1.1
- 65febe4 Bump acorn from 7.1.0 to 7.1.1
- 2d8045f test 3 spaces before table rows
- 431f523 remove unneeded code
- d8c09c1 add tests
- cbcda26 copy table rules to nptables
- 11a035e build [skip ci]
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.