bump @mdx-js/mdx version to latest #8702
Labels
closed: duplicate
This issue or pull request already exists in another issue or pull request
closed: please-fix-this-cve
This issue is asking for fixing a CVE in a build-only dep which doesn't pose any real threat.
Have you read the Contributing Guidelines on issues?
Motivation
@docusaurus/mdx-loader
due to transitive dependencies.https://www.mend.io/vulnerability-database/CVE-2020-7753
https://security.snyk.io/vuln/SNYK-JS-TRIM-1017038
"@mdx-js/mdx": "^1.6.22"
has transitive dependency onremark-parse
, which has dependency ontrim-0.0.1
. Updating@mdx-js/mdx
to latest version2.3.0
will remove vulnerable dependencies.@docusaurus/core
due to transitive dependencies.https://www.mend.io/vulnerability-database/CVE-2022-33987
"update-notifier": "^5.1.0",
has transitive dependency ongot-9.6.0
. Updating it to latest version will remove vulnerabile dependencies.Self-service
The text was updated successfully, but these errors were encountered: