Package
gitlab-rails-ce-assets-fips-19.4
Component
markdown
Latest update
Aliases
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
The flagged component is the editor's bundled 'markdown' VS Code language-support extension manifest (/srv/gitlab/public/assets/webpack/gitlab-web-ide-vscode-workbench-0.0.1-dev-20260106142046/vscode/extensions/markdown-basics/package.json), which declares its own unrelated version number and contributes only a TextMate grammar and language configuration. None of the 'markdown' npm library code is present in this package, so the vulnerable code is not shipped.
Status
Impact
Waiting on upstream to publish a fixed version for this vulnerability.
Status