Skip to content

Security: nagayev/highlight.js

Security

SECURITY.md

Security Policy

Supported Versions

Due to both time and resource constrains the Highlight.js core team only fully supports the most current major/minor release of the library. Problems with prior minor releases are often solved by upgrading to the most recent minor release. Prior major release will only receive critical security updates (when feasible).

Version Status
10.3.x The 10.x series recieves regular updates, new features & bug fixes.
<= 10.2.x Please upgrade to a more recent release.
9.18.x 🔐 Security updates only. See VERSION_10_UPGRADE.md.
<= 9.17.x Obsolete.
8.x Obsolete.
7.x Obsolete.
Older Obsolete.

Version 9

Support for IE11 is really the only reason anyone should still prefer version 9. It's recommended that everyone else upgrade.

Reporting a Vulnerability

Minor vulnerabilities can simply be reported (and tracked) via our GitHub issues. If you feel your issue is more sensitive than that you can always reach us via email: security@highlightjs.org

There aren’t any published security advisories