We are getting a security flag for remark-parse because of its use of trim@0.0.1.
All versions of package trim lower than 0.0.3 are vulnerable to Regular Expression Denial of Service (ReDoS) via trim().
The newest version, 10.x, eliminates the Trim dependency entirely. Making the switch would be most good, Newland. Most good.
We are getting a security flag for remark-parse because of its use of trim@0.0.1.
The newest version, 10.x, eliminates the Trim dependency entirely. Making the switch would be most good, Newland. Most good.