After 96 releases, 368 pull requests, and over 48 million downloads, I’m pleased to share that the next major version of league/commonmark 2.0.0 stable is now generally available! 🎉🎉
You can install the latest version via Composer:
composer require league/commonmark:^2.0
What’s new in 2.0?
There’s so much to cover, but here are the key improvements and changes:
This will likely be the last minor release of 1.x as we focus efforts on developing 2.0. This post breaks down some of the new features and changes you should know about 1.5.0.
Three New Extensions
The popular Markdown library now includes three more extensions within core thanks for to the community:
After 5 years of development, 3,000,000 downloads, and 58 releases, I’m extremely pleased to announce that league/commonmark version 1.0.0 has been released!
This weekend I’ve tagged the first pre-releases of the 1.x branch! I strongly encourage everyone to test their applications and extensions against this beta and provide any feedback. (Helpful information can be found in the upgrading guide.) Unless there are any major issues we’ll plan on releasing a stable 1.0.0 version in the coming weeks!
A cross-site scripting (XSS) vulnerability was found in the PHP League’s CommonMark library (league/commonmark) versions 0.15.6 through 0.18.x before 0.18.1. It allows remote attackers to insert unsafe URLs into <a> tags (even if allow_unsafe_links is false) by adding an encoded newline character in the middle (e.g., writing javascript as javascri%0Apt).
Version 0.18.1 has been released to fix this issue. All users are strongly encouraged to upgrade to this version.