tuchk4 / storybook-readme

React Storybook addon to render README files in github style

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Vulnerability in dependency `marked`

sareh opened this issue · comments

commented

There is a vulnerability in the dependency marked that is used in this package: https://github.com/tuchk4/storybook-readme/blob/master/packages/storybook-readme/package.json

https://www.npmjs.com/advisories/1076/versions.
It is fixed in version 0.7.0

will publish today later

commented

Thank you, @tuchk4.

Looks good in 5.0.8 - thanks @tuchk4!

@sareh @dtesta released in 5.0.8

@sareh thanks for PR :)

commented

We are trying to use version 6.0.28 and seeing this vulnerability https://snyk.io/vuln/SNYK-JS-TRIM-1017038