manuelgeek/vuejs-medium-editor

package.json dependency on "pure-gist-embed" involves a security vulnerability

Opened this issue · 2 comments

Apparently tui2tone/gist-embed (aka pure-gist-embed) hasn't been updated for several years now.
It pulls axios with a known security vulnerability:
Screenshot 2024-04-30 at 5 36 29 PM

Screenshot 2024-04-30 at 5 43 19 PM

Maybe it's time to replace it (?)

do you have an alternative in mind? @igal1c0de4n

sorry - I don't have sufficient experience with the desired functionality nor with packages which may replace it