From 4d68a3489752631757dba8c4ce5836009d6cba8a Mon Sep 17 00:00:00 2001 From: Tom Moor Date: Wed, 28 Apr 2021 22:44:05 -0700 Subject: [PATCH] fix: ReDoS attack vulnerability when searching documents that contain many space characters see: https://github.com/outline/outline/pull/2097 see: https://snyk.io/vuln/SNYK-JS-REMOVEMARKDOWN-73635 --- package.json | 2 +- yarn.lock | 8 ++++---- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/package.json b/package.json index c5698943..923e977f 100644 --- a/package.json +++ b/package.json @@ -78,7 +78,7 @@ "@sentry/react": "^6.3.1", "@sentry/tracing": "^6.3.1", "@tippy.js/react": "^2.2.2", - "@tommoor/remove-markdown": "0.3.1", + "@tommoor/remove-markdown": "^0.3.2", "autotrack": "^2.4.1", "aws-sdk": "^2.831.0", "babel-plugin-lodash": "^3.3.4", diff --git a/yarn.lock b/yarn.lock index 1fb56a3f..2bbf3171 100644 --- a/yarn.lock +++ b/yarn.lock @@ -1989,10 +1989,10 @@ prop-types "^15.6.2" tippy.js "^4.3.4" -"@tommoor/remove-markdown@0.3.1": - version "0.3.1" - resolved "https://registry.yarnpkg.com/@tommoor/remove-markdown/-/remove-markdown-0.3.1.tgz#25e7b845d52fcfadf149a3a6a468a931fee7619b" - integrity sha512-aM5TtBfBgcUm+B4WWelm2NBAFBk12oNUr67f5lJapSOTkPnwkuzCNwMlsBoDTsRknoZSsUIkcOJB473AnfyqHA== +"@tommoor/remove-markdown@^0.3.2": + version "0.3.2" + resolved "https://registry.yarnpkg.com/@tommoor/remove-markdown/-/remove-markdown-0.3.2.tgz#5288ddd0e26b6b173e76ebb31c94653b0dcff45d" + integrity sha512-awcc9hfLZqyyZHOGzAHbnjgZJpQGS1W1oZZ5GXOTTnbKVdKQ4OWYbrRWPUvXI2YAKJazrcS8rxPh67PX3rpGkQ== "@types/babel__core@^7.0.0", "@types/babel__core@^7.1.7": version "7.1.12"