mozilla / missioncontrol

Real-time monitoring of Firefox release health
Mozilla Public License 2.0
20 stars 18 forks source link

Bump markdown-to-jsx from 6.6.0 to 6.11.4 #388

Open dependabot[bot] opened 4 years ago

dependabot[bot] commented 4 years ago

Bumps markdown-to-jsx from 6.6.0 to 6.11.4.

Release notes

Sourced from markdown-to-jsx's releases.

6.11.4: Mitigates security vulnerability where maliciously crafted markdown links could use data: or vbscript: urls to trigger an xss injection ( #306 / https://www.npmjs.com/advisories/1219 ), even when using options.disableParsingRawHTML

Note that currently, the default options.disableParsingRawHTML = false should still only be used for trusted input, as arbitrary html, including script tags.

6.11.3 has no changes (I held the publish script upside down; the only change from 6.11.2 is the version number šŸ˜…)

6.11.2

[FIX] - Footnote references (#304) thanks @csantos1113

6.11.1

Fix: Support empty style attribute (#296) thanks @cribbles

6.11.0

  • Optionally disable HTML parsing (#278)
  • Fix HTML multiline comments bug (#246) (#262)

6.10.3

6.10.2

[security] Sanitize href values (#249) by @coreyward

6.10.1

add new option namedCodesToUnicode (#236) (#253) by @JeremiasEh

6.10.0

[XSS] Ignore case of blacklisted HTML elements (#247) by @jakelazaroff

6.9.4

fix a table rendering issue when the first cell is blank #241 thanks @simezi

6.9.3

fix an html perf regression edge case #234

6.9.2

#238 Fix overriding of props, thanks @mstruebing

6.9.1

ac97191bd857340efbd2840e0ffc5b7dd5cbdae3 ensure there's a key set for every output

6.9.0

a slew of regex optimizations; the library should be more performant now for blocks of text with several instances of bold/em/etc

6.8.4

graceful fallback for missing footnotes (#227)

6.8.3

Actually fix support for React's various new object-based components like React.forwardRef

Commits
Maintainer changes

This version was pushed to npm by ariabuckles, a new releaser for markdown-to-jsx since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/mozilla/missioncontrol/network/alerts).