Upgrade markedjs from 2.1.3 to 4.0.12

Bug #1961856 reported by Dianne Tennent
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Mahara
Fix Released
High
Dianne Tennent
20.10
Fix Released
High
Unassigned
21.04
Fix Released
High
Unassigned
21.10
Fix Released
High
Unassigned
22.04
Fix Released
High
Dianne Tennent

Bug Description

Moving to v4 due to major security fixes

https://github.com/markedjs/marked/security/advisories

Revision history for this message
Robert Lyon (robertl-9) wrote :
Changed in mahara:
milestone: none → 22.04.0
importance: Undecided → High
status: New → In Progress
Changed in mahara:
assignee: nobody → Dianne Tennent (dianne-t)
Revision history for this message
Robert Lyon (robertl-9) wrote (last edit ):

Note: 20.10 and 21.04 will be upgrading from older versions of marked.js so may need cherry-pick of older patch(es) and will need proper testing

Gold (gold.catalyst)
information type: Private Security → Public Security
Revision history for this message
Mahara Bot (dev-mahara) wrote : A patch has been submitted for review

Patch for "21.04_DEV" branch: https://reviews.mahara.org/c/mahara/+/12668

Revision history for this message
Mahara Bot (dev-mahara) wrote : A change has been merged

Reviewed: https://reviews.mahara.org/c/mahara/+/12668
Committed: https://git.mahara.org/mahara/mahara/commit/f0e8efc1088c82152f8dc5e37809bfcdf2ad1e87
Submitter: "Robert Lyon <email address hidden>"
Branch: 21.04_DEV

commit f0e8efc1088c82152f8dc5e37809bfcdf2ad1e87
Author: Dianne Tennent <email address hidden>
Date: Wed Feb 23 14:34:45 2022 +1300

Security Bug 1961856: Upgrade markedjs from 2.1.3 to 4.0.12

Change-Id: I52df433b13705b35b888d1e4caefb7b6fd9e3787

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.