Closed divya-layerhealth closed 4 weeks ago
MathJax <= 2.7.9 has a high-severity ReDoS vulnerability.
To mitigate, at the very minimum we should upgrade the default MathJax version to v3.x.
In addition, I noticed that PR https://github.com/danielfrg/mkdocs-jupyter/pull/201 introduced a custom_mathjax_url override, but that it was subsequently removed in PR https://github.com/danielfrg/mkdocs-jupyter/pull/211 -- was there a reason for this/should it be added back?
custom_mathjax_url
Happy to make both of these changes myself if that helps!
I dont think we had a real reason to remove it tbh. I think we should have it.
If you can get a PR that would be great!
Awesome! https://github.com/danielfrg/mkdocs-jupyter/pull/226
MathJax <= 2.7.9 has a high-severity ReDoS vulnerability.
To mitigate, at the very minimum we should upgrade the default MathJax version to v3.x.
In addition, I noticed that PR https://github.com/danielfrg/mkdocs-jupyter/pull/201 introduced a
custom_mathjax_url
override, but that it was subsequently removed in PR https://github.com/danielfrg/mkdocs-jupyter/pull/211 -- was there a reason for this/should it be added back?Happy to make both of these changes myself if that helps!