Skip to content

Conversation

@snyk-bot
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-MARKDOWNIT-2331914
No No Known Exploit
medium severity 586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-MARKED-2342073
No Proof of Concept
medium severity 586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-MARKED-2342082
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: jsdoc The new version differs by 10 commits.
  • c5ea65a 3.6.8
  • a024054 update dependencies
  • e1f1919 3.6.7
  • f7a64bd chore(deps): update selected dependencies
  • 3f5c462 3.6.6
  • 95e3192 fix: correctly track interface members
  • ef05a69 3.6.5
  • a59b5cd fix: prevent circular refs when params have the same type expression
  • 8d0fce6 chore: bump version; update release notes
  • 91c9aa7 chore(deps): update dependencies

See the full diff

Package name: markdownlint The new version differs by 250 commits.
  • 2d19c06 Update to version 0.25.1.
  • 61bb059 Make all package.json dependency versions explicit for more deterministic installs.
  • 66d533d Update npx invocation to pass --yes to avoid prompting to install missing packages.
  • 23d8ed7 Add test case for custom rule that imports an ESM module (refs #477).
  • b1aef98 Empty commit to note that previous commit fixes #478.
  • f77eca0 Update dependency: markdown-it to 12.3.2.
  • 05b4b5f Update copyright year to 2022.
  • 02707cf Merge branch 'next' into main
  • 4ff4cbc Update to version 0.25.0.
  • e298e3d Include async/await function in custom rules test for asynchronous mode.
  • 11e9a20 Update dependency: globby to 12.0.2.
  • 05b9e6e Update dependency: strip-json-comments to 4.0.0.
  • 528758e Update dependencies: eslint to 8.5.0, eslint-plugin-jsdoc to 37.4.0.
  • fd24b95 Remove require("os") from helpers to reduce dependencies for browser scenarios.
  • 9ec14f1 Include custom rule markdownlint-rule-github-internal-links when validating project Markdown files.
  • 5f00406 Deep freeze name/tokens/lines/frontMatterLines properties of params object before passing to (custom) rules for shared access.
  • 5253669 Fix array indexing for markdownlint-disable-next-line when front matter is present.
  • 7a76f1d Update MD039/no-space-in-links to fix reference-style links, be slightly more permissive matching link content.
  • 064a1e3 Update Node version for TestRepos workflow from 12 to 16.
  • ff8f4ea Reduce execution time by ~50% by updating getEnabledRulesPerLineNumber to make enabledRules immutable and copy only when changed (also, simplify handleInlineConfig slightly).
  • 7cf9c2d Update MD037/no-space-in-emphasis to ignore embedded underscore emphasis markers (fixes #444, fixes #408, fixes #354, fixes #324).
  • 3e8d332 Add test for outdated ignore expressions to markdownlint-test-repos.
  • 6dea678 Update definition of helpers.isBlankLine to treat unterminated start/end comments as potentially blank lines (fixes #431).
  • 1b23976 Update dependencies: eslint-plugin-jsdoc to 37.2.8, eslint-plugin-unicorn to 39.0.0.

See the full diff

Package name: markdownlint-cli The new version differs by 174 commits.
  • fec244c Bump version 0.31.0
  • a0527a8 Set two more Prettier options explicitly for a consistent experience (refs #247).
  • e45d433 Enable "Prettier" validation for "xo", configure settings for minimal non-space deltas, apply all required changes (fixes #246, closes #247).
  • 4baec11 Update to invoke execa as an ESM import.
  • f771c6b Bump execa from 5.1.1 to 6.0.0
  • c327fb5 Update to invoke get-stdin as an ESM import.
  • aca74ca Bump get-stdin from 8.0.0 to 9.0.0
  • c48be7b Bump commander from 8.3.0 to 9.0.0 (#256)
  • e1f0f3b fix: vuln in markdown > markdown-it (#255)
  • 3009422 Bump ava from 3.15.0 to 4.0.1 (#253)
  • 5276c70 Update dependency: markdownlint to 0.25.0.
  • 18eb72d Bump actions/setup-node from 2.5.0 to 2.5.1 (#251)
  • 38956ca Bump markdownlint-rule-helpers from 0.15.0 to 0.16.0 (#250)
  • 318c1c3 Bump ignore from 5.1.9 to 5.2.0 (#248)
  • c5a8b48 Standardize and improve exit code handling (#245)
  • 799ed61 chore: Add Node 17 to CI matrix (#244)
  • e3f5a6c chore: use built-in setup-node NPM cache (#243)
  • 219cc3b Bump actions/setup-node from 2.4.1 to 2.5.0 (#242)
  • 3e989a4 Bump xo from 0.46.4 to 0.47.0 (#241)
  • 2ea8a2c Remove unused/outdated helper packages, replace with native JavaScript functions (fixes #237).
  • 328dacc Bump version 0.30.0
  • 27dc20f Add exitCode check to all tests.
  • bf8b148 Rebuild package-lock.json to try to fix "npm ci".
  • 27d5e70 Update CI workflow to include linting step.

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants