8000 update prismJS to 1.30.0 by przemyslawjanpietrzak · Pull Request #74 · wooorm/refractor · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

update prismJS to 1.30.0 #74

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

8000 Already on GitHub? Sign in to your account

Conversation

przemyslawjanpietrzak
Copy link

prims < 1.30.0 has some XSS vulnerability

@wooorm
Copy link
Owner
wooorm commented Mar 11, 2025

Oh? Wouldn’t that be listed in the changelog? https://github.com/PrismJS/prism/releases/tag/v1.30.0 And, wouldn’t a patch release be used for fixes instead of a minor release?

@neethan
Copy link
neethan commented Mar 11, 2025

Oh? Wouldn’t that be listed in the changelog? https://github.com/PrismJS/prism/releases/tag/v1.30.0 And, wouldn’t a patch release be used for fixes instead of a minor release?

Seems the linked PR notes that it fixes the vulnerability: PrismJS/prism#3863

The changelog for that release seems just a regular autogen'd changelog via Github, rather than a proper changelog. I guess they don't follow semver strictly ;)

@wooorm
Copy link
Owner
wooorm commented Mar 11, 2025

I do not see that affects this project; please read the code of this project. That code is not here. Prism is not a dependency of this project and this project is not vulnerable.

@wooorm
Copy link
Owner
wooorm commented Mar 11, 2025

This PR does not work

@wooorm wooorm closed this Mar 11, 2025
@wooorm
Copy link
Owner
wooorm commented Mar 11, 2025

Working on a release

@wooorm
Copy link
Owner
wooorm commented Mar 11, 2025

there’s a release pulling in prism 1.30. And a new major. But, importantly: this project was never vulnerable

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants
0