Skip to content

Conversation

@drolsen
Copy link

@drolsen drolsen commented Apr 20, 2019

Latest version of NPM is complaining that this plugin's usage of the marked module needs to be manually updated due to Regular Expression Denial of Service vulnerability (https://www.npmjs.com/advisories/786).

I've updated the package.json file to the patched version NPM recommends (0.6.2) and it seems to have resolved the vulnerability issue.

Unsure if the update has effected the core functionality of this plugin as there are no test scripts.
Please confirm core functionality of docgen-loader still works prior to merging.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant