Looks like there's a Regular Expression Denial of Service (ReDoS) vulnerability in marked package version 0.6.0 according to the advisory here: https://www.npmjs.com/advisories/1076
Upgrading the package should fix it. I can put up a PR to fix that :)
lock files updated at https://github.com/tuchk4/storybook-readme/commit/2daddf43abc4803fb9a32ef8d05a103a32acbbcf
Thanks
Does it usually take long to publish these to npm? I just tried doing npm audit fix and it still says this:
1 vulnerability required manual review and could not be updated
Still an issue in 5.0.6
For anyone following, new open issue @ #204
Most helpful comment
Still an issue in 5.0.6