Avast keeps identifying that Joplin is infected with md:httprequest-inf [sups] and quarantining the file. The constant pop-ups are annoying but the real question is this is really malware.
I have had this 5 times since April 20. I just checked, the last md false positive indeed contains an HTTPS link to a commercial website which was perfectly legit the last time I checked. I have 5 md files in quarantine, all with the same file name, but a different name in config\joplin-desktop\tmp. I checked each of those 5 files and Avast each time extracted the same exact file; I don't know if Avast is stuck or if it has indeed detected 5 times the same file under different names and decided to store them all under the same name in quarantine.