Skip to content

[Harness SCS] Security upgrade markdown-it to version 14.2.0 - #406

Open
jatin471 wants to merge 1 commit into
mainfrom
harness-scs/fix-fee8ae6f
Open

jatin471 wants to merge 1 commit into
mainfrom
harness-scs/fix-fee8ae6f

Conversation

@jatin471

Copy link
Copy Markdown

Harness has created this PR to fix risky or vulnerable packages.

📁 Changes included in this PR

Changes to the following files to upgrade the vulnerable dependencies to a fixed version:

  • ctfd/data/CTFd/package.json

📝 Description

Upgrade Version: 14.2.0


🛡️ Security Impact

Current version vulnerabilities: 2 (Critical: 0, High: 0, Medium: 2, Low: 0)

Severity CVSS Score Upgrade Version Reference Identifiers
medium severity 5.3 - CVE-2026-48988, GHSA-6v5v-wf23-fmfq, CWE-400, CWE-407
medium severity 5.3 - CVE-2022-21670, GHSA-6vfc-qv3f-vr6c, CWE-400, CWE-1333

Upgrade version vulnerabilities: 1 (Critical: 0, High: 0, Medium: 0, Low: 1)

Severity CVSS Score Upgrade Version Reference Identifiers
low severity 3.5 14.2.0 GHSA-253c-mchw-3w2r

Status: 🎉 1 vulnerabilities have been reduced/resolved.


📦 Dependencies affected

Dependency Name Change Type Vulnerabilities
linkify-it MODIFIED 🔴 C:0 | 🟠 H:0 | 🟡 M:0 | ⚪ L:0
punycode.js ADDED 🔴 C:0 | 🟠 H:0 | 🟡 M:0 | ⚪ L:0
argparse MODIFIED 🔴 C:0 | 🟠 H:0 | 🟡 M:0 | ⚪ L:0
entities MODIFIED 🔴 C:0 | 🟠 H:0 | 🟡 M:0 | ⚪ L:0
mdurl MODIFIED 🔴 C:0 | 🟠 H:0 | 🟡 M:0 | ⚪ L:0

👤 Created By

This PR was automatically created by Harness Auto Remediation.


Note

This PR is generated by Harness Supply Chain Security and contains changes based on AI recommendations. It is recommended to review the changes before merging.

This branch was successfully deployed

No deployments
development — 22c84779 Deployed Oct 11, 2026 by jatin471 via Build, Secret Scan, and Generate SBOM #429
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant