-
Notifications
You must be signed in to change notification settings - Fork 35
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Replace marked library with 8fold-marked #82
Comments
XSS fix: markedjs/marked#844, applied at https://github.com/8fold/marked/commit/8f9d0b72f5606ed32057049f387161dd41c36ade Note also #40 exists since a while, asking for better defaults. |
marked library was updated to cover the XSS issues and tagged as 0.3.9 |
@stramel thanks. For being horribly paranoid: could this project explicitly bump the library requirement to 0.3.9? |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Description
The https://github.com/chjj/marked project seems to be unmaintained right now, and instead there is https://github.com/8fold/marked. This contains at least one additional XSS fix, which this element should pick up.
Expected outcome
8fold-marked is used.
Actual outcome
marked is used.
The text was updated successfully, but these errors were encountered: