Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade mavon-editor from 3.0.0-beta to 3.0.1 #235

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

bangbang93
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-HIGHLIGHTJS-1048676
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: mavon-editor The new version differs by 39 commits.
  • cf622a8 Released version 3.0.1
  • 6e6ea4a Merge pull request #845 from jiawulin001/next
  • d0af7c7 Merge branch 'next' into next
  • 1be10ab [sync fca6c62] chore: upgrade xss version
  • ca9c29b [sync a0f6ac2]doc: update maekdown.md
  • 9b44e1a [sync e48e75e] refactor: provides a standard interface to get markdown-it
  • adc5594 [sync 61f8663] fix: error while uploading image
  • 9a8bcc1 [sync b9489a3] fix: Add sanitizer for filtering HTML tags
  • b66474b [sync 8a2eb2a] Create SECURITY.md
  • 9938dcf [sync 9933119] fix: image cannot be previewed
  • 0f8d445 [sync ca87152] Add vue3 version badge
  • fa382b8 [sync 2a6fa04] doc: update markdown.md
  • 4b02104 [sync 4937828]doc: Additional notes
  • 28c9347 [sync 3ea9622] doc: document style
  • def6b59 [sync bf97a96]添加了一个在编辑器外渲染markdown的例子
  • 2895e76 [sync cd409d9]doc: customize and add toolbar buttons
  • 6cbfc57 [sync c611bdd]fix: Fix the content of code blocks to be displayed outside the pre container
  • 417f66e [sync 720c987]Fix build warnings and optimize console output
  • de44fb3 Sync Log.md file
  • e94a598 fix eslint error
  • 116e79a [sync d7ff5f2] Add switch code style demo and build to add checks
  • 3aea5b9 [sync 77e2ce6] Fix code style function and text alignment function
  • 8767096 [sync ab3f7f9]feat: Enable XSS defense by default
  • f2920f6 [sync 03cb80a]注入HTML到document前,默认对渲染成的HTML进行防XSS过滤处理

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants