valeriangalliat / markdown-it-highlightjs

Preset to use highlight.js with markdown-it.
The Unlicense
54 stars 30 forks source link

Highlight.js Potential ReDOS vulnerabilities #16

Closed angelaman closed 3 years ago

angelaman commented 3 years ago

Hi guys,

I read here, highlight.js versions prior 10.4.1 are all vulnerable to potential ReDOS attacks. markdown-it-highlightjs currently depends on version 10.2.0. Can you update it to version 10.4.1 instead? Thanks!

valeriangalliat commented 3 years ago

We depend on ^10.2.0 which means a npm upgrade will allow you to use further semver-compatible versions like 10.4.1 :)