wooorm / refractor

Lightweight, robust, elegant virtual syntax highlighting using Prism

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Backporting Prism 1.24 to v3 for security fix?

mayank99 opened this issue · comments

See high severity vulnerability: GHSA-gj77-59wh-66hg

Because refractor@3 uses ~1.23.0 instead of ^, users need to force resolve to the patched version (I know this is a mild inconvenience, so feel free to close this issue).

commented

Not sure why Prism didn’t release it in a patch. But, released.