-
Notifications
You must be signed in to change notification settings - Fork 26
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix(deps): update dependency dompurify to v3 [security] #3063
base: main
Are you sure you want to change the base?
Conversation
The latest updates on your projects. Learn more about Vercel for Git ↗︎
|
|
f1669ef
to
f86b96c
Compare
f86b96c
to
47ca4d0
Compare
47ca4d0
to
674dff3
Compare
674dff3
to
9e1a511
Compare
9e1a511
to
8bd77c7
Compare
8bd77c7
to
d734d57
Compare
d734d57
to
a61a670
Compare
a61a670
to
6582010
Compare
This PR contains the following updates:
2.5.8
->3.2.4
GitHub Vulnerability Alerts
CVE-2025-26791
DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS).
Release Notes
cure53/DOMPurify (dompurify)
v3.2.4
: DOMPurify 3.2.4Compare Source
v3.2.3
: DOMPurify 3.2.3Compare Source
v3.2.2
: DOMPurify 3.2.2Compare Source
v3.2.1
Compare Source
v3.2.0
: DOMPurify 3.2.0Compare Source
v3.1.7
: DOMPurify 3.1.7Compare Source
foreignObject
element from the list of HTML entry-points, thanks @masatokinugawav3.1.6
: DOMPurify 3.1.6Compare Source
v3.1.5
: DOMPurify 3.1.5Compare Source
bower.js
, thanks @HakumenNCv3.1.4
: DOMPurify 3.1.4Compare Source
isNaN
checks, thanks @tulachv3.1.3
: DOMPurify 3.1.3Compare Source
nodeType
property, thanks @ssi02014v3.1.2
: DOMPurify 3.1.2Compare Source
v3.1.1
: DOMPurify 3.1.1Compare Source
Note that this is a security release and should be upgraded to immediately. Please also note that further releases may follow as the underlying vulnerability is apparently new and further variations may be discovered.
v3.1.0
: DOMPurify 3.1.0Compare Source
SAFE_FOR_XML
to enable better control over comment scrubbingv3.0.11
: DOMPurify 3.0.11Compare Source
v3.0.10
: DOMPurify 3.0.10Compare Source
v3.0.9
: DOMPurify 3.0.9Compare Source
hasOwnProperty
logic, thanks @ssi02014console.warn
making HappyDom happier, thanks @HugoPoiv3.0.8
: DOMPurify 3.0.8Compare Source
v3.0.7
: DOMPurify 3.0.7Compare Source
v3.0.6
: DOMPurify 3.0.6Compare Source
v3.0.5
: DOMPurify 3.0.5Compare Source
v3.0.4
: DOMPurify 3.0.4Compare Source
shadowrootmod
which should beshadowrootmode
, thanks @masatokinugawav3.0.3
: DOMPurify 3.0.3Compare Source
TRUSTED_TYPES_POLICY
configuration option, thanks @dejangfeDropShadow
to the SVG filter allow-list, thanks @SelfMadeSystemv3.0.2
: DOMPurify 3.0.2Compare Source
ALLOWED_URI_REGEXP
not being reset, thanks @mukilanemprescripts
tag to allowed MathML elements, thanks @duyhai94v3.0.1
: DOMPurify 3.0.1Compare Source
v3.0.0
: DOMPurify 3.0.0Compare Source
ALLOW_SELF_CLOSE_IN_ATTR
flag, thanks @edg2s @AndreVirtimoshadowrootmode
, thanks @mfreed7NOTE Please use the 2.4.4 release if you still need MSIE support, 3.0.0 comes without the MSIE overhead
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.