oracle-samples / cerner-smart-embeddable-lib

npm project for developers to use in their SMART web app to be embeddable in Cerner’s MPage Workflow
Apache License 2.0
22 stars 31 forks source link

Vulnerability in marked < 0.3.9 #5

Closed mkwhitacre closed 6 years ago

mkwhitacre commented 6 years ago

Known moderate severity security vulnerability detected in marked < 0.3.9 defined in package-lock.json.

package-lock.json update suggested: marked ~> 0.3.9.

kolkheang commented 6 years ago

Already addressed with https://github.com/cerner/cerner-smart-embeddable-lib/pull/4. Although, I don't think package-lock.json is needed. Will remove it in the future.

mjhenkes commented 6 years ago

npm recommends that you check in into version control, so I think thats fine. https://docs.npmjs.com/files/package-lock.json

mkwhitacre commented 6 years ago

Cool that if it is addressed.