Skip to content

Conversation

@Mitko-Kerezov
Copy link
Contributor

@Mitko-Kerezov Mitko-Kerezov commented Jan 5, 2018

Update marked dependency to latest version and regenerate npm-shrinkwrap.
This is done as marked 0.3.6 has some security vulnerabilities, which have been resolved in 0.3.9 as can be seen from the Github analysis

Ping @TsvetanMilanov @KristianDD @rosen-vladimirov

@Mitko-Kerezov Mitko-Kerezov self-assigned this Jan 5, 2018
@KristianDD
Copy link
Contributor

Could you add some more information why we update the dependency please.

@Mitko-Kerezov
Copy link
Contributor Author

@KristianDD modified the PR description to point out why this change is proposed

Copy link
Contributor

@rosen-vladimirov rosen-vladimirov left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The shrinkwrap is incorrect - some optional dependencies have been removed. It looks like the shrinkwrap has been generated on Windows with npm version below 5.6.0

@rosen-vladimirov
Copy link
Contributor

I've updated the branch with correct shrinkwrap. I've also updated marked version to 0.3.12

@rosen-vladimirov rosen-vladimirov merged commit f35dbfc into master Jan 15, 2018
@rosen-vladimirov rosen-vladimirov deleted the kerezov/update-marked branch January 15, 2018 09:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

5 participants