github drasimwagan/mdv v0.2.1
v0.2.1 — security patch

latest release: vscode-v0.2.1
2 hours ago

A security patch release. Upgrading is recommended for anyone who renders .mdv/.md files they didn't write themselves.

Security

  • Denial of service on crafted documents (ReDoS) fixed. A single very long ::: or code-fence line containing a lone carriage return (\r) or a Unicode line/paragraph separator (U+2028/U+2029) made the ::: pre-pass take quadratic time. That was about 0.4 s at 40,000 characters and minutes at 1 MB, which hung mdv render, mdv preview and the VS Code preview. Line handling is now linear-time: the same 1 MB input renders in about 250 ms. It's covered by regression tests. Found by CodeQL code scanning. (#71)
  • GitHub Actions pinned to commit SHAs. Every workflow action, including the third-party release action, is now referenced by an immutable commit SHA instead of a movable version tag. (#71)

Fixed

  • Classic-Mac (lone \r) line endings. Documents saved with bare \r line endings now parse exactly like LF/CRLF documents. Previously, ::: directives and code fences weren't recognized in such files. (#71)

Compatibility

No syntax or API changes. For documents with LF or CRLF line endings, output is byte-identical to 0.2.0.

Get it

  • CLI / library: build from this tag (git checkout v0.2.1 && npm ci && npm run build). npm publishing is planned (roadmap Phases 14–15).
  • VS Code extension: see the VS Code extension v0.2.1 release for the .vsix.

Full changelog: CHANGELOG.md [0.2.1] · v0.2.0...v0.2.1

Don't miss a new mdv release

NewReleases is sending notifications on new releases.