markdown
Safeguard articles tagged "markdown" — guides, analysis, and best practices for software supply chain and application security.
5 articles
react-md-editor: Using @uiw/react-md-editor Securely
How to use react-md-editor safely: what @uiw/react-md-editor does, the XSS risk in markdown preview, and why rehype-sanitize is not optional for untrusted input.
Showdown Markdown Converter: XSS Risks and Safe Configuration
The npm showdown library converts Markdown to HTML without sanitizing it — by design. Here is where the XSS risk actually lives and how to render untrusted Markdown safely.
Rendering Markdown Securely in React Native with react-native-markdown-display
react-native-markdown-display is the maintained way to render Markdown in React Native, but rendering untrusted Markdown safely takes more than dropping in the component. Here is the security guide.
Is turndown on npm Safe? A Security Review
turndown converts HTML to Markdown with no known CVEs, but the real risk is what you do with its input and output. Here is how to use it safely.
marked on npm: Security Review and Safe Usage
marked is a fast Markdown parser, but it does not sanitize output and older versions carried a ReDoS bug. Here is how to use marked npm without opening an XSS hole.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.