A security patch release. Upgrading is recommended for anyone who renders .mdv/.md files they didn't write themselves.
Security
- Denial of service on crafted documents (ReDoS) fixed. A single very long
:::or code-fence line containing a lone carriage return (\r) or a Unicode line/paragraph separator (U+2028/U+2029) made the:::pre-pass take quadratic time. That was about 0.4 s at 40,000 characters and minutes at 1 MB, which hungmdv render,mdv previewand the VS Code preview. Line handling is now linear-time: the same 1 MB input renders in about 250 ms. It's covered by regression tests. Found by CodeQL code scanning. (#71) - GitHub Actions pinned to commit SHAs. Every workflow action, including the third-party release action, is now referenced by an immutable commit SHA instead of a movable version tag. (#71)
Fixed
- Classic-Mac (lone
\r) line endings. Documents saved with bare\rline endings now parse exactly like LF/CRLF documents. Previously,:::directives and code fences weren't recognized in such files. (#71)
Compatibility
No syntax or API changes. For documents with LF or CRLF line endings, output is byte-identical to 0.2.0.
Get it
- CLI / library: build from this tag (
git checkout v0.2.1 && npm ci && npm run build). npm publishing is planned (roadmap Phases 14–15). - VS Code extension: see the VS Code extension v0.2.1 release for the
.vsix.
Full changelog: CHANGELOG.md [0.2.1] · v0.2.0...v0.2.1