Skip to content
This repository was archived by the owner on Sep 16, 2019. It is now read-only.

[Security update] 0.0.13 #229

Merged
merged 5 commits into from
Jun 14, 2018
Merged

[Security update] 0.0.13 #229

merged 5 commits into from
Jun 14, 2018

Conversation

yhatt
Copy link
Owner

@yhatt yhatt commented Jun 14, 2018

This is a security update caused by a mention of https://github.com/yhatt/marp/issues/187#issuecomment-396781598.

We have recognized that v0.0.12 still has a remaining way to be able accessing to the content of the local resource (CVE-2017-2239). We are setting CSP for scripts to minimize exploit.

This update will affect a few expert users using the external local script in Markdown (e.g. Chart rendering), but this change has limited impact.

In future

For security, we are planning the next-gen Marp will limit execution of any scripts.

To migrate to next-gen marp, we are not planning of minor upgrade / additional features for current Marp.

@yhatt yhatt merged commit 70abebb into master Jun 14, 2018
@yhatt yhatt deleted the 0.0.13 branch June 14, 2018 03:25
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant