brunobarretofreitas / md-to-pdfmake

Easily parse markdown text to pdfmake compatible objects
MIT License
5 stars 2 forks source link

Depends on vulnerable versions of marked #1

Open defname opened 9 months ago

defname commented 9 months ago
# npm audit report

marked  <=4.0.9
Severity: high
Inefficient Regular Expression Complexity in marked - https://github.com/advisories/GHSA-rrrm-qjm4-v8hf
Inefficient Regular Expression Complexity in marked - https://github.com/advisories/GHSA-5v2h-r2cx-5xgj
No fix available
node_modules/md-to-pdfmake/node_modules/marked
  md-to-pdfmake  *
  Depends on vulnerable versions of marked
  node_modules/md-to-pdfmake

2 high severity vulnerabilities

Would be great if you find time to fix this dependency

Wojciech404 commented 2 days ago

Hello. I have create a PR for this: https://github.com/brunobarretofreitas/md-to-pdfmake/pull/4