Skip to content

Conversation

@matthew-heath
Copy link

@matthew-heath matthew-heath commented Mar 21, 2024

Bumping prismjs to 1.29.0 to fix vulnerability alert produced in private repositories by dependabot (#434)
Screenshot 2024-03-21 at 11 22 05

Related CVE - https://www.cvedetails.com/cve/CVE-2022-23647/?q=CVE-2022-23647

@matthew-heath matthew-heath changed the title Bump prismjs to 1.29.0 Bump prismjs to 1.29.0 to clear Dependabot security alert. Mar 21, 2024
@matthew-heath matthew-heath changed the title Bump prismjs to 1.29.0 to clear Dependabot security alert. Bump prismjs to 1.29.0 to clear Dependabot vulnerability alert. Mar 21, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant