jbt / docker

Documentation generator
http://jbt.github.com/docker
MIT License
234 stars 56 forks source link

dox 0.8.1 dependency vulnerability #111

Open leviwheatcroft opened 6 years ago

leviwheatcroft commented 6 years ago

My repo's with docker in the package-lock are showing a security vulnerability for marked < 0.3.9:

The dependency is docker > dox@^0.8.0 > marked

dox@0.9.0 switched to markdown-it for markdown. The version release message notes that this might be a breaking change as markdown output would change.

Any thoughts about what problems we might encounter upgrading to dox@0.9.0 ?