Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

bump @mdx-js/mdx version to latest #8702

Closed
1 of 4 tasks
prajwalmr62 opened this issue Feb 23, 2023 · 1 comment
Closed
1 of 4 tasks

bump @mdx-js/mdx version to latest #8702

prajwalmr62 opened this issue Feb 23, 2023 · 1 comment
Labels
closed: duplicate This issue or pull request already exists in another issue or pull request closed: please-fix-this-cve This issue is asking for fixing a CVE in a build-only dep which doesn't pose any real threat.

Comments

@prajwalmr62
Copy link

prajwalmr62 commented Feb 23, 2023

Have you read the Contributing Guidelines on issues?

Motivation

  • The following vulnerability is thrown for the latest version of @docusaurus/mdx-loader due to transitive dependencies.

https://www.mend.io/vulnerability-database/CVE-2020-7753
https://security.snyk.io/vuln/SNYK-JS-TRIM-1017038

"@mdx-js/mdx": "^1.6.22" has transitive dependency on remark-parse, which has dependency on trim-0.0.1. Updating @mdx-js/mdx to latest version 2.3.0 will remove vulnerable dependencies.

  • The following vulnerability is thrown for the latest version of @docusaurus/core due to transitive dependencies.

https://www.mend.io/vulnerability-database/CVE-2022-33987

"update-notifier": "^5.1.0", has transitive dependency on got-9.6.0. Updating it to latest version will remove vulnerabile dependencies.

Self-service

  • I'd be willing to do some initial work on this proposal myself.
@prajwalmr62 prajwalmr62 added proposal This issue is a proposal, usually non-trivial change status: needs triage This issue has not been triaged by maintainers labels Feb 23, 2023
@slorber
Copy link
Collaborator

slorber commented Feb 23, 2023

😅 I'm working on this upgrade for months now: #8288 #4029

@slorber slorber closed this as not planned Won't fix, can't repro, duplicate, stale Feb 23, 2023
@slorber slorber added closed: duplicate This issue or pull request already exists in another issue or pull request and removed status: needs triage This issue has not been triaged by maintainers proposal This issue is a proposal, usually non-trivial change labels Feb 23, 2023
@Josh-Cena Josh-Cena added the closed: please-fix-this-cve This issue is asking for fixing a CVE in a build-only dep which doesn't pose any real threat. label Feb 23, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
closed: duplicate This issue or pull request already exists in another issue or pull request closed: please-fix-this-cve This issue is asking for fixing a CVE in a build-only dep which doesn't pose any real threat.
Projects
None yet
Development

No branches or pull requests

3 participants