Bump dompurify from 3.2.7 to 3.4.0#1301
Conversation
|
@flavorjones would it be possible/safe to merge this and release 🙏. Since current version of dompurify is raising 9 security vulnerabilities(moderate)? |
|
My bad fixed security issues by updating to the latest trix version(2.1.18). Sorry for spamming :) |
|
@dependabot recreate |
Bumps [dompurify](https://github.com/cure53/DOMPurify) from 3.2.7 to 3.4.0. - [Release notes](https://github.com/cure53/DOMPurify/releases) - [Commits](cure53/DOMPurify@3.2.7...3.4.0) --- updated-dependencies: - dependency-name: dompurify dependency-version: 3.4.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
28c71a1 to
5d1708a
Compare
There was a problem hiding this comment.
Pull request overview
Updates the bundled DOMPurify version used by Trix (and the ActionText-Trix packaged asset) to incorporate upstream security fixes and behavior corrections.
Changes:
- Update the lockfile to resolve
dompurifyfrom3.2.7to3.4.0. - Regenerate the bundled
action_text-trixJavaScript asset to embed DOMPurify3.4.0(including upstream sanitization fixes and config-handling changes).
Tip
If you aren't ready for review, convert to a draft PR.
Click "Convert to draft" or run gh pr ready --undo.
Click "Ready for review" or run gh pr ready to reengage.
Reviewed changes
Copilot reviewed 1 out of 2 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
yarn.lock |
Locks DOMPurify to 3.4.0 for reproducible installs. |
action_text-trix/app/assets/javascripts/trix.js |
Updates the vendored/bundled DOMPurify code and version header to 3.4.0. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
Superseded by #1310 |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps dompurify from 3.2.7 to 3.4.0.
Release notes
Sourced from dompurify's releases.
Commits
5b16e0bGetting 3.x branch ready for 3.4.0 release (#1250)8bcbf73chore: Preparing 3.3.3 release5faddd6fix: engine requirement (#1210)0f91e3aUpdate README.mdd5ff1a8Merge branch 'main' of github.com:cure53/DOMPurifyc3efd48fix: moved back from jsdom 28 to jsdom 20988b888fix: moved back from jsdom 28 to jsdom 202726c74chore: Preparing 3.3.2 release6202c7ebuild(deps): bump@tootallnate/onceand jsdom (#1204)302b51dfix: Expanded the regex ever so slightly to also cover script