Skip to content

Commit e623b72

Browse files
authored
Merge pull request #1690 from hackmdio/feature/upgrade-mermaid-8.10.1
Upgrade mermaid to version 8.10.2 to avoid prototype pollution
2 parents 82b7800 + 16a1e82 commit e623b72

File tree

5 files changed

+21
-64
lines changed

5 files changed

+21
-64
lines changed

package-lock.json

+17-60
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

package.json

+1-1
Original file line numberDiff line numberDiff line change
@@ -167,7 +167,7 @@
167167
"markdownlint-rule-helpers": "^0.13.0",
168168
"markmap-lib": "^0.4.2",
169169
"mathjax": "~2.7.5",
170-
"mermaid": "~8.6.4",
170+
"mermaid": "~8.10.2",
171171
"mini-css-extract-plugin": "~0.4.1",
172172
"mocha": "~5.2.0",
173173
"mock-require": "~3.0.3",

public/views/codimd/foot.ejs

+1-1
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@
1010
<script src="https://cdnjs.cloudflare.com/ajax/libs/mathjax/2.7.0/config/TeX-AMS-MML_HTMLorMML.js" integrity="sha256-immzXfCGLhnx3Zfi9F/dUcqxEM8K3o3oTFy9Bh6HCwg=" crossorigin="anonymous" defer></script>
1111
<script src="https://cdnjs.cloudflare.com/ajax/libs/mathjax/2.7.0/config/Safe.js" integrity="sha256-0ygBUDksNDXZS4vm5HMNH1a33KUu6QT1cdNTN+ZLF+4=" crossorigin="anonymous" defer></script>
1212
<script src="https://cdnjs.cloudflare.com/ajax/libs/moment.js/2.24.0/moment-with-locales.min.js" integrity="sha256-AdQN98MVZs44Eq2yTwtoKufhnU+uZ7v2kXnD5vqzZVo=" crossorigin="anonymous" defer></script>
13-
<script src="https://cdnjs.cloudflare.com/ajax/libs/mermaid/8.6.4/mermaid.min.js" integrity="sha512-kaov70mb/084wHYwVZLxTsCaq04AED9ksQaxgXXxbciHDdD8HAR8z7wNEfLLg8LgM5eu4J+tCfAsaIFoYsdVfw==" crossorigin="anonymous" defer></script>
13+
<script src="https://cdnjs.cloudflare.com/ajax/libs/mermaid/8.10.2/mermaid.min.js" integrity="sha512-UjRGY3wuX8Jnhbf5r71wM8QtR/xr/BzflZ8znqfCuBOxeuzNjGmfjaU3AIeHph7fZuqx1bEbZ6Iq2zBsrHAIsQ==" crossorigin="anonymous" defer></script>
1414
<script src="https://cdn.jsdelivr.net/npm/@hackmd/[email protected]/dist/js/emojify-browser.min.js" integrity="sha256-swgfXtqk2bC98KzPoE8tXRz5tmrzpjJWhhXlhYo/wRA=" crossorigin="anonymous" defer></script>
1515
<script src="https://cdnjs.cloudflare.com/ajax/libs/lodash.js/4.17.2/lodash.min.js" integrity="sha256-Cv5v4i4SuYvwRYzIONifZjoc99CkwfncROMSWat1cVA=" crossorigin="anonymous" defer></script>
1616
<script src="https://cdnjs.cloudflare.com/ajax/libs/socket.io/2.1.1/socket.io.js" integrity="sha256-ji09tECORKvr8xB9iCl8DJ8iNMLriDchC1+p+yt1hSs=" crossorigin="anonymous"></script>

public/views/pretty.ejs

+1-1
Original file line numberDiff line numberDiff line change
@@ -88,7 +88,7 @@
8888
<script src="https://cdnjs.cloudflare.com/ajax/libs/mathjax/2.7.0/config/TeX-AMS-MML_HTMLorMML.js" integrity="sha256-immzXfCGLhnx3Zfi9F/dUcqxEM8K3o3oTFy9Bh6HCwg=" crossorigin="anonymous" defer></script>
8989
<script src="https://cdnjs.cloudflare.com/ajax/libs/mathjax/2.7.0/config/Safe.js" integrity="sha256-0ygBUDksNDXZS4vm5HMNH1a33KUu6QT1cdNTN+ZLF+4=" crossorigin="anonymous" defer></script>
9090
<script src="https://cdnjs.cloudflare.com/ajax/libs/moment.js/2.24.0/moment-with-locales.min.js" integrity="sha256-AdQN98MVZs44Eq2yTwtoKufhnU+uZ7v2kXnD5vqzZVo=" crossorigin="anonymous" defer></script>
91-
<script src="https://cdnjs.cloudflare.com/ajax/libs/mermaid/8.6.4/mermaid.min.js" integrity="sha512-kaov70mb/084wHYwVZLxTsCaq04AED9ksQaxgXXxbciHDdD8HAR8z7wNEfLLg8LgM5eu4J+tCfAsaIFoYsdVfw==" crossorigin="anonymous" defer></script>
91+
<script src="https://cdnjs.cloudflare.com/ajax/libs/mermaid/8.10.2/mermaid.min.js" integrity="sha512-UjRGY3wuX8Jnhbf5r71wM8QtR/xr/BzflZ8znqfCuBOxeuzNjGmfjaU3AIeHph7fZuqx1bEbZ6Iq2zBsrHAIsQ==" crossorigin="anonymous" defer></script>
9292
<script src="https://cdn.jsdelivr.net/npm/@hackmd/[email protected]/dist/js/emojify-browser.min.js" integrity="sha256-swgfXtqk2bC98KzPoE8tXRz5tmrzpjJWhhXlhYo/wRA=" crossorigin="anonymous" defer></script>
9393
<script src="https://cdnjs.cloudflare.com/ajax/libs/handlebars.js/4.1.2/handlebars.min.js" integrity="sha256-ngJY93C4H39YbmrWhnLzSyiepRuQDVKDNCWO2iyMzFw=" crossorigin="anonymous" defer></script>
9494
<script src="https://cdnjs.cloudflare.com/ajax/libs/highlight.js/9.15.10/highlight.min.js" integrity="sha256-1zu+3BnLYV9LdiY85uXMzii3bdrkelyp37e0ZyTAQh0=" crossorigin="anonymous" defer></script>

public/views/slide.ejs

+1-1
Original file line numberDiff line numberDiff line change
@@ -100,7 +100,7 @@
100100
<script src="https://cdnjs.cloudflare.com/ajax/libs/mathjax/2.7.0/config/TeX-AMS-MML_HTMLorMML.js" integrity="sha256-immzXfCGLhnx3Zfi9F/dUcqxEM8K3o3oTFy9Bh6HCwg=" crossorigin="anonymous" defer></script>
101101
<script src="https://cdnjs.cloudflare.com/ajax/libs/mathjax/2.7.0/config/Safe.js" integrity="sha256-0ygBUDksNDXZS4vm5HMNH1a33KUu6QT1cdNTN+ZLF+4=" crossorigin="anonymous" defer></script>
102102
<script src="https://cdnjs.cloudflare.com/ajax/libs/moment.js/2.24.0/moment-with-locales.min.js" integrity="sha256-AdQN98MVZs44Eq2yTwtoKufhnU+uZ7v2kXnD5vqzZVo=" crossorigin="anonymous" defer></script>
103-
<script src="https://cdnjs.cloudflare.com/ajax/libs/mermaid/8.6.4/mermaid.min.js" integrity="sha512-kaov70mb/084wHYwVZLxTsCaq04AED9ksQaxgXXxbciHDdD8HAR8z7wNEfLLg8LgM5eu4J+tCfAsaIFoYsdVfw==" crossorigin="anonymous" defer></script>
103+
<script src="https://cdnjs.cloudflare.com/ajax/libs/mermaid/8.10.2/mermaid.min.js" integrity="sha512-UjRGY3wuX8Jnhbf5r71wM8QtR/xr/BzflZ8znqfCuBOxeuzNjGmfjaU3AIeHph7fZuqx1bEbZ6Iq2zBsrHAIsQ==" crossorigin="anonymous" defer></script>
104104
<script src="https://cdn.jsdelivr.net/npm/@hackmd/[email protected]/dist/js/emojify-browser.min.js" integrity="sha256-swgfXtqk2bC98KzPoE8tXRz5tmrzpjJWhhXlhYo/wRA=" crossorigin="anonymous" defer></script>
105105
<script src="https://cdnjs.cloudflare.com/ajax/libs/handlebars.js/4.1.2/handlebars.min.js" integrity="sha256-ngJY93C4H39YbmrWhnLzSyiepRuQDVKDNCWO2iyMzFw=" crossorigin="anonymous" defer></script>
106106
<script src="https://cdnjs.cloudflare.com/ajax/libs/highlight.js/9.15.10/highlight.min.js" integrity="sha256-1zu+3BnLYV9LdiY85uXMzii3bdrkelyp37e0ZyTAQh0=" crossorigin="anonymous" defer></script>

0 commit comments

Comments
 (0)