Skip to content

Commit c57d268

Browse files
author
Chetan Karande
committed
Fix insecure dependency
1 parent d479bbd commit c57d268

File tree

1 file changed

+1
-3
lines changed

1 file changed

+1
-3
lines changed

package.json

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -14,16 +14,14 @@
1414
"express-session": "^1.13.0",
1515
"forever": "^0.15.1",
1616
"helmet": "^2.0.0",
17-
"marked": "0.3.5",
17+
"marked": "0.3.9",
1818
"mongodb": "^2.1.18",
1919
"node-esapi": "0.0.1",
2020
"serve-favicon": "^2.3.0",
2121
"swig": "^1.4.2",
2222
"underscore": "^1.8.3"
2323
},
2424
"comments": {
25-
"//": "do not upgrade the marked package version it is set by purpose",
26-
"//": "to be a vulnerable package to demonstrate an xss introduced through",
2725
"//": "a9 insecure components"
2826
},
2927
"engines": {

0 commit comments

Comments
 (0)