From 3c51991c32aaa2b002a52c009334ebe5752c84b3 Mon Sep 17 00:00:00 2001 From: Vitaly Puzrin Date: Fri, 11 Sep 2026 06:50:26 +0300 Subject: [PATCH] 15.0.2 released --- CHANGELOG.md | 8 ++++++++ package.json | 2 +- 2 files changed, 9 insertions(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 245d50a..8db4407 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,6 +5,13 @@ All notable changes to this project will be documented in this file. The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/), and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). +## [15.0.2] - 2026-09-11 + +### Security +- Fixed quadratic complexity in smartquotes when quote types don't match, #1209. + Also limited the smartquotes stack to 1000 unmatched openers. + + ## [15.0.1] - 2026-08-27 ### Changed @@ -742,6 +749,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 - Renamed presets folder (configs -> presets). +[15.0.2]: https://github.com/markdown-it/markdown-it/compare/15.0.1...15.0.2 [15.0.1]: https://github.com/markdown-it/markdown-it/compare/15.0.0...15.0.1 [15.0.0]: https://github.com/markdown-it/markdown-it/compare/14.3.0...15.0.0 [14.3.0]: https://github.com/markdown-it/markdown-it/compare/14.2.0...14.3.0 diff --git a/package.json b/package.json index 47c4b6f..e42c651 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "markdown-it", - "version": "15.0.1", + "version": "15.0.2", "description": "Markdown-it - modern pluggable markdown parser.", "keywords": [ "markdown",