Skip to content

fix: Intra-word emphasis can match the wrong asterisks - #1636

Merged
styfle merged 3 commits into
markedjs:masterfrom
Scrum:master
Apr 10, 2020
Merged

fix: Intra-word emphasis can match the wrong asterisks#1636
styfle merged 3 commits into
markedjs:masterfrom
Scrum:master

Conversation

@Scrum

@Scrum Scrum commented Apr 3, 2020

Copy link
Copy Markdown
Contributor

Description

Contributor

  • Test(s) exist to ensure functionality and minimize regression (if no tests added, list tests covering this PR)

Committer

In most cases, this should be a different person than the contributor.

  • Draft GitHub release notes have been updated.
  • CI is green (no forced merge required).
  • Merge PR

@vercel

vercel Bot commented Apr 3, 2020

Copy link
Copy Markdown

This pull request is being automatically deployed with ZEIT Now (learn more).
To see the status of your deployment, click below or on the icon next to each commit.

🔍 Inspect: https://zeit.co/markedjs/markedjs/qba5ws1f2
✅ Preview: https://markedjs-git-fork-scrum-master.markedjs.now.sh

@UziTech

UziTech commented Apr 3, 2020

Copy link
Copy Markdown
Member

@davisjam could you check if the new regex is vulnerable to ReDos?

@Scrum

Scrum commented Apr 9, 2020

Copy link
Copy Markdown
Contributor Author

@UziTech @davisjam ping ?

@UziTech UziTech left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It doesn't looks like this changes the structure of the regex so if it wasn't vulnerable before than it shouldn't be now.

Good work! 💯

@styfle styfle left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks!

@styfle
styfle merged commit 71e96bb into markedjs:master Apr 10, 2020
@UziTech UziTech mentioned this pull request Apr 13, 2020
@UziTech UziTech mentioned this pull request Apr 20, 2020
12 tasks
zhenalexfan pushed a commit to zhenalexfan/MarkdownHan that referenced this pull request Nov 8, 2021
fix: Intra-word emphasis can match the wrong asterisks
zhenalexfan pushed a commit to zhenalexfan/MarkdownHan that referenced this pull request Nov 8, 2021
fix: Intra-word emphasis can match the wrong asterisks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants