gucong3000 / postcss-markdown

PostCSS Syntax for parsing Markdown
MIT License
21 stars 10 forks source link

chore: 🤖 bump remark version to v13.0.0 #37

Closed kreuzerk closed 3 years ago

kreuzerk commented 3 years ago

Hi there. The current version of postcss-markdown includes remark@11.x which has a library called trim as dependency. trim itself has some vulnerabilities.

I went through the Changelog of remark and I think it should be okay to bump this version. Also, all tests are still passing. However, I don't know postcss-markdown enough to evaluate the impact of this change. @gucong3000 @Chersquwn do you think it's safe to bump the version?