Huge News!Announcing our $40M Series B led by Abstract Ventures.Learn More
Socket
Sign inDemoInstall
Socket

mavon-editor-xss

Package Overview
Dependencies
Maintainers
1
Versions
3
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

mavon-editor-xss

Vue markdown editor

  • 2.9.3
  • latest
  • Source
  • npm
  • Socket score

Version published
Weekly downloads
1
Maintainers
1
Weekly downloads
 
Created
Source

文档详见原项目

说明

这个包修复了mavonEditor@2.9.0存在的xss问题. 虽然官方打了补丁,但是仍然需要自行配置xss规则,且对预览模式不生效.查看了源码之后, 发现mavonEditor是基于markdown-it开发的,其本身具有xss方面配置项.现在修改配置 后打包供自己现有项目使用.

现在在文本中输入HTML标签会被过滤,如果有展示HTML标签的需要,请使用markdown语法中 的代码块包裹,即可正常显示.

Keywords

FAQs

Package last updated on 25 Sep 2020

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts

SocketSocket SOC 2 Logo

Product

  • Package Alerts
  • Integrations
  • Docs
  • Pricing
  • FAQ
  • Roadmap
  • Changelog

Packages

npm

Stay in touch

Get open source security insights delivered straight into your inbox.


  • Terms
  • Privacy
  • Security

Made with ⚡️ by Socket Inc