jsdoc2md / dmd

The default output template for jsdoc2md
MIT License
39 stars 49 forks source link

Upgrade dependencies #74

Closed eaviles closed 5 years ago

eaviles commented 5 years ago

Fixes vulnerability on the “marked” module. As reported in: https://www.npmjs.com/advisories/812

eaviles commented 5 years ago

@75lb I'll appreciate you review this PR, let me know if I need to do something else.

75lb commented 5 years ago

hi, could you explain how a remote hacker could exploit this vulnerability in jsdoc2md and what damage could be done?

eaviles commented 5 years ago

There's a detailed explanation at: https://snyk.io/vuln/SNYK-JS-MARKED-174116

75lb commented 5 years ago

OK, so how would a remote hacker exploit a DDoS vulnerability in jsdoc2md?

75lb commented 5 years ago

Duplicate of https://github.com/jsdoc2md/dmd/pull/73.