lemaur / markdown
Another Markdown parsers but with super powers
Fund package maintenance!
Requires
- php: ^8.2
- illuminate/contracts: ^11.0 || ^12.0 || ^13.0
- league/commonmark: ^2.0
- spatie/laravel-package-tools: ^1.4.3
Requires (Dev)
- ergebnis/composer-normalize: ^2.42
- laravel/pint: ^1.0
- orchestra/testbench: ^9.0 || ^10.0 || ^11.0
- phpstan/phpstan-deprecation-rules: ^1.1.1 || ^2.0
- phpstan/phpstan-phpunit: ^1.3.3 || ^2.0
- phpunit/phpunit: ^11.0 || ^12.0
- spatie/phpunit-snapshot-assertions: ^5.0
README
Support Me
Hey folks,
Do you like this package? Do you find it useful and it fits well in your project?
I am glad to help you, and I would be so grateful if you considered supporting my work.
You can even choose 😃:
- You can sponsor me 😎 with a monthly subscription.
- You can buy me a coffee ☕ or a pizza 🍕 just for this package.
- You can plant trees 🌴. By using this link we will both receive 30 trees for free and the planet (and me) will thank you.
- You can "Star ⭐" this repository (it's free 😉).
Installation
You can install the package via composer:
composer require lemaur/markdown
You can publish the config file with:
php artisan vendor:publish --provider="Lemaur\Markdown\MarkdownServiceProvider" --tag="markdown-config"
Usage
use Lemaur\Markdown; $markdown = <<<'MD' # Title a paragraph with [link](https://website.com). <x-custom-component></x-custom-component> MD; return Markdown::render($markdown);
Code blocks are safe: any Blade-looking syntax inside a fenced (```), indented,
or inline (`) code block is displayed as literal text, never executed. So you can
document components without them rendering:
```blade <x-custom-component></x-custom-component> ```
This code-block protection is based on Aaron Francis' article Rendering Blade Components in Markdown.
⚠️ Only render trusted content.
Markdown::render()runs the Blade compiler over the document body (outside code blocks), so any Blade or PHP in the prose is executed. Never pass user-generated Markdown to it. Protection covers CommonMark code constructs only — raw HTML<pre>/<code>you write by hand is treated as HTML and is not shielded from Blade.
Testing
composer test
Changelog
Please see CHANGELOG for more information on what has changed recently.
Contributing
Please see CONTRIBUTING for details.
Security Vulnerabilities
Please review our security policy on how to report security vulnerabilities.
Credits
- Maurizio
- Aaron Francis — the code-block protection approach is based on his article Rendering Blade Components in Markdown
- All Contributors
License
The MIT License (MIT). Please see License File for more information.