SassDoc / sassdoc-theme-default

Default theme for SassDoc.
MIT License
10 stars 30 forks source link

Updated to sassdoc-extras@3.0.0 #114

Closed dominikwilkowski closed 4 years ago

dominikwilkowski commented 4 years ago

The version of sassdoc-extras below v3.0.0 includes marked@^0.6.2 which comes with a security advisory.

pascalduez commented 4 years ago

sassdoc-extra@3.x remove support for Node versions lower than 8, which sassdoc and sassdoc-theme-default still provide. That would mean releasing a major version for both of those packages, which is not yet planned. Maybe just force update sassdoc-extra in your project, with something like yarn's resolutions?

dominikwilkowski commented 4 years ago

I mean I hear you and the issue you got but the package is currently causing security warnings in my repos. Would it be a thing to release a hotfix for sassdoc-extras@2.5.1 that just bumps marked? I'll close this issue for now

pascalduez commented 4 years ago

Would it be a thing to release a hotfix for sassdoc-extras@2.5.1 that just bumps marked

It's actually the marked update that remove older Node versions support...