DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-23rc-4693-gfcx

Package

gitlab-rails-ce-19.3

Component

markdown-it

Latest update

Pending upstream fix

Aliases

Severity

Unknown
Eliminate CVEs with Chainguard hardened images

Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.

Start for free

References

  • https://github.com/advisories/GHSA-253c-mchw-3w2r

Updates

Status

Pending upstream fix

Impact

GHSA-253c-mchw-3w2r (https://github.com/advisories/GHSA-253c-mchw-3w2r) is fixed in markdown-it 14.3.1. This copy of markdown-it is one of GitLab's frontend dependencies (/srv/gitlab/yarn.lock) and is kept at 14.2.0. Every fixed markdown-it release (14.3.1 and later) uses JavaScript syntax that GitLab's frontend build does not compile: GitLab builds its assets with webpack 4 and does not transpile markdown-it, so the package fails to build with a fixed markdown-it. GitLab itself still ships markdown-it 14.1.0 (https://gitlab.com/gitlab-org/gitlab/-/blob/master/yarn.lock). Waiting for the first upstream release containing the fix.

Status

Under investigation


The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.