From 296564a4ceddcd5989efdfca3c9c6cfea7a6bc9b Mon Sep 17 00:00:00 2001 From: Marc Jansen Date: Tue, 18 Aug 2015 21:21:51 +0200 Subject: [PATCH] Use a more recent version of marked Quoting from https://nodesecurity.io/advisories/marked_redos: > Marked 0.3.3 and earlier is vulnerable to regular expression denial of > service (ReDoS) when certain types of input are passed in to be parsed. --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index a007b94861..0fc8cc01d1 100644 --- a/package.json +++ b/package.json @@ -33,7 +33,7 @@ "graceful-fs": "3.0.2", "handlebars": "3.0.1", "jsdoc": "3.3.2", - "marked": "0.3.3", + "marked": "0.3.5", "metalsmith": "1.6.0", "metalsmith-templates": "0.7.0", "nomnom": "1.8.0",