Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Thanks for this great tool!
Purpose: This PR updates the
marked
dependency by bumping its patch version.Background:
marked
@0.3.6 has two security vulnerabilities (https://nvd.nist.gov/vuln/detail/CVE-2017-1000427, https://nvd.nist.gov/vuln/detail/CVE-2017-17461). While these are not exposed given how typedoc usesmarked
- the vulnerability warning is passed through to all repos that depend ontypedoc
. This creates a burden of keeping track of what vulnerabilities are actual - and desensitizes the github tool.It is unclear why files beyond
package.json
changed. I noticed the same changes simply by cloning the repo and installing - so they don't seem related to this PR. If you'd like me to remove them from this PR, I'd be happy. Just let me know!