Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Request for Release] Can we please release a 0.3.7 version? #938

Closed
joshbruce opened this issue Sep 21, 2017 · 8 comments
Closed

[Request for Release] Can we please release a 0.3.7 version? #938

joshbruce opened this issue Sep 21, 2017 · 8 comments

Comments

@joshbruce
Copy link
Member

joshbruce commented Sep 21, 2017

I'm working on a project with some very tight security protocols. There is a vulnerability, that I believe is fixed on master; however, a new version has not been released. The editor I use (simplemde) uses the latest version of Marked by default; so, as soon as the release is made, I can get this approved in my environment.

Please.

uswds/uswds#2149

https://www.npmjs.com/package/8fold-marked

@fboes
Copy link

fboes commented Sep 25, 2017

I second that idea, as David DM now marks marked as unsecure (e.g. see https://david-dm.org/fboes/blogophon). For some unlucky folks this means that on their project page their project is marked as unsecure.

@matt-
Copy link
Contributor

matt- commented Sep 26, 2017

The person that owns the project will not respond / push a new version and us maintainers on github can't push to NPM.

I would consider this project dead. I would be happy to consider a fork or maybe people should look into something like markdown-it.

@joshbruce
Copy link
Member Author

@matt- I was afraid that would be the case. Do you know if others feel the same? (I mean with 300+ Issues and 150+ PRs can't imagine it not being the case.)

(I really do hope @chjj is all right...recent activity seems a little light in comparison.)

Everyone is welcome to head over to 8fold/marked. I will be happy to add collaborators to the repo and NPM for the project (don't know the details of how and process for releases yet, but we'll get it sorted).

This seems to be one of the more popular Markdown libraries going and I don't think the broader community is ready to abandon it wholesale. If there's a way to get the owner to transfer ownership, 8fold is willing to take that on as well to maintain the "marked" package name and whatnot.

@colinalford-gsa

@joshbruce joshbruce changed the title [Request for Release] Can we please release a 3.7 version? [Request for Release] Can we please release a 0.3.7 version? Sep 26, 2017
@fboes
Copy link

fboes commented Sep 27, 2017

As for the time being I switched to https://www.npmjs.com/package/8fold-marked, but will return to the original as soon as it is patched.

@joshbruce
Copy link
Member Author

We just did release 0.3.8 with a performance enhancement.

https://github.com/8fold/marked/pull/1

There are two more PRs in the queue:

https://github.com/8fold/marked/pulls

I don't know demand for those; so, not sure the urgency. Looks like they were pulled over from PRs submitted here that the submitters were waiting on.

@joshbruce
Copy link
Member Author

Also we have another collaborator for the library with write access; so, I believe they should be able to accept PRs. Invited @matt- as well. So, far I'm not too concerned about the bottleneck at NPM yet. Trying to build a core team...temporary as it may or may not become.

@joshbruce
Copy link
Member Author

Reached out to @chjj to see about transferring the project to 8fold. We'll see how that goes.

@joshbruce
Copy link
Member Author

As I have been granted publishing rights to NPM and collaborator rights on the repo, I will close this issue for now. See #956 and #951.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants