-
Notifications
You must be signed in to change notification settings - Fork 35
New issue
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
Replace marked library with 8fold-marked #82
Comments
XSS fix: markedjs/marked#844, applied at https://github.com/8fold/marked/commit/8f9d0b72f5606ed32057049f387161dd41c36ade Note also #40 exists since a while, asking for better defaults. |
marked library was updated to cover the XSS issues and tagged as 0.3.9 |
@stramel thanks. For being horribly paranoid: could this project explicitly bump the library requirement to 0.3.9? |
# for free
to join this conversation on GitHub.
Already have an account?
# to comment
Description
The https://github.com/chjj/marked project seems to be unmaintained right now, and instead there is https://github.com/8fold/marked. This contains at least one additional XSS fix, which this element should pick up.
Expected outcome
8fold-marked is used.
Actual outcome
marked is used.
The text was updated successfully, but these errors were encountered: