-
-
Notifications
You must be signed in to change notification settings - Fork 359
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
posibility of a 8.0.4 release with less strict trim version dependecy #710
Comments
This is unlikely to affect you. You could use |
More of an mdx-js/mdx issue: you’ve seen the reports and results there. |
except remark-mdx@1.6.22 which is used by @mdx-js/mdx@1.6.22 which is used by @storybook/addon-docs@6.2.9. A patch release of |
I'm amazed. Is releasing a patch version that opens for patch updates of "trim" really that hard to accomplish that it is instead suggested to use unstable "next"-releases? EDIT: even if that is your opionion, i would still consider hart patchlevel pinning of dependency a bug, as this is blocking potential security updates. |
It's impossible to not pin 0.0.1. I raised that 5 years ago: component/trim#7 (comment) |
As noted in mdx-js/mdx#1548 (comment), MDX 2 is one option.
Please read the advisory https://www.npmjs.com/advisories/1700 |
This is true for this situation. But still it would be a lot nicer/easier to have a way to handle this without doing a major update, which makes a lot of people, especially QA-People, nervous
oh man, what a strange part of our dependcy tree. I think we need to prioritize some updates for our app. |
hey @wooorm, I don't quite understand why it's impossible to not pin that dependency. I think I am missing something. Can you elaborate a bit? |
https://semver.org/#spec-item-4. Before semver |
Subject of the issue
The 8.0 branch of
remark-parse
requires trim in verison "0.0.1", which has a security problem (see: https://www.npmjs.com/advisories/1700).Is there any posibility that you could release an update to 8.0.3 (ie 8.0.4) that introduces a less strict version dependency for trim?
The text was updated successfully, but these errors were encountered: