SassDoc / sassdoc-extras

Extra tools for SassDoc theme builders
MIT License
3 stars 7 forks source link

Regular Expression Denial of Service in 'marked' dependency before 0.6.2 (sassdoc-extras 2.5.0) #40

Closed Ambient-Impact closed 5 years ago

Ambient-Impact commented 5 years ago

Hi there. I was just running npm audit, and got this for sassdoc-extras:

  Moderate        Regular Expression Denial of Service

  Package         marked

  Patched in      >=0.6.2

  Dependency of   grunt-sassdoc [dev]

  Path            grunt-sassdoc > sassdoc > sassdoc-theme-default >
                  sassdoc-extras > marked

  More info       https://npmjs.com/advisories/812

Hopefully an updated version of marked can be used in this project soon? Thanks.