Bump dompurify from 2.4.4 to 3.1.2
Bumps dompurify from 2.4.4 to 3.1.2.
Release notes
Sourced from dompurify's releases.
DOMPurify 3.1.2
- Addressed and fixed a mXSS variation found by
@kevin-mizu
- Addressed and fixed a mXSS variation found by Adam Kues of Assetnote
- Updated tests for older Safari and Chrome versions
DOMPurify 3.1.1
- Fixed an mXSS sanitiser bypass reported by
@icesfont
- Added new code to track element nesting depth
- Added new code to enforce a maximum nesting depth of 255
- Added coverage tests and necessary clobbering protections
Note that this is a security release and should be upgraded to immediately. Please also note that further releases may follow as the underlying vulnerability is apparently new and further variations may be discovered.
DOMPurify 3.1.0
- Added new setting
SAFE_FOR_XML
to enable better control over comment scrubbing- Updated README to warn about happy-dom not being safe for use with DOMPurify yet
- Updated the LICENSE file to show the accurate year number
- Updated several build and test dependencies
DOMPurify 3.0.11
- Fixed another conditional bypass caused by Processing Instructions, thanks
@Ry0taK
- Fixed the regex for HTML Custom Element detection, thanks
@AlekseySolovey3T
DOMPurify 3.0.10
- Fixed two possible bypasses when sanitizing an XML document and later using it in HTML, thanks
@Slonser
- Bumped up some build and test dependencies
DOMPurify 3.0.9
- Fixed a problem with proper detection of Custom Elements, thanks
@kevin-mizu
- Refactored the
hasOwnProperty
logic, thanks@ssi02014
- Removed a superfluous
console.warn
making HappyDom happier, thanks@HugoPoi
- Modernized some of the demo hooks for better looks, thanks
@Steb95
DOMPurify 3.0.8
- Fixed errors caused by conditional exports, thanks
@ssi02014
- Fixed a type error when working with custom element config, thanks
@cpmotion
DOMPurify 3.0.7
- Added better protection against CSPP attacks, thanks
@kevin-mizu
- Updated browser versions for automated tests
- Updated Node versions for automated tests
- Refactored code base, thanks
@ssi02014
- Refactored build system & deployment, thanks
@ssi02014
DOMPurify 3.0.6
- Refactored the core code-base and several utilities, thanks
@ssi02014
- Updated and fixed several sections of the README, thanks
@ssi02014
- Updated several outdated build and test dependencies
DOMPurify 3.0.5
... (truncated)
Commits
-
5b2e317
Merge pull request #945 from cure53/main -
74664db
chore: Updated package-lock.json with new release number -
5f17b27
chore: Preparing 3.1.2 release -
5d492ee
test: Fixed the tests for older Chrome and Safari -
8075b37
fix: Adjusted the list of permitted SVG HTML integration points -
61b761f
fix: Switched to using the getParentNode API for some calls -
ee17313
docs: Added new mentions of honor to the readme -
7a0a984
Merge pull request #944 from cure53/main -
7bbd12b
chore: Preparing 3.1.1 release -
87eff29
Merge branch 'main' of github.com:cure53/DOMPurify - Additional commits viewable in compare view
Dependabot commands
You can trigger Dependabot actions by commenting on this MR
-
$dependabot rebase
will rebase this MR -
$dependabot recreate
will recreate this MR rewriting all the manual changes and resolving conflicts