Bump dompurify from 2.4.4 to 3.0.4
Bumps dompurify from 2.4.4 to 3.0.4.
Release notes
Sourced from dompurify's releases.
DOMPurify 3.0.4
- Fixed a bypass in jsdom 22 in case the noframes element is permitted, thanks
@leeN
- Fixed a typo with
shadowrootmod
which should beshadowrootmode
, thanks@masatokinugawa
DOMPurify 3.0.3
- Added new
TRUSTED_TYPES_POLICY
configuration option, thanks@dejang
- Added
feDropShadow
to the SVG filter allow-list, thanks@SelfMadeSystem
DOMPurify 3.0.2
- Fixed an issue with
ALLOWED_URI_REGEXP
not being reset, thanks@mukilane
- Added
mprescripts
tag to allowed MathML elements, thanks@duyhai94
- Added SMS URI scheme to allowed URI schemes, tanks
@Kiwka
- Updated supported browser versions for nicer code and smaller size, thanks
@buzinas
DOMPurify 3.0.1
- Fixed a problem with improper reset of custom HTML options, thanks
@ammaraskar
DOMPurify 3.0.0
- Removed all code that is for MSIE-only
- Removed all tests that are for MSIE-only
- Modified documentation to reflect new state of MSIE support
- Added support for
ALLOW_SELF_CLOSE_IN_ATTR
flag, thanks@edg2s
@AndreVirtimo
- Added better support for
shadowrootmode
, thanks@mfreed7
NOTE Please use the 2.4.4 release if you still need MSIE support, 3.0.0 comes without the MSIE overhead
DOMPurify 2.4.6
- Fixed a bypass in jsdom 22 in case the
noframes
element is permitted, thanks@leeN
DOMPurify 2.4.5
- Fixed a problem with improper reset of custom HTML options, thanks
@ammaraskar
Commits
-
1777363
chore: Updated package-lock.json with latest version number -
8c8007c
Merge branch 'main' of github.com:cure53/DOMPurify -
5a04182
chore: Preparing 3.0.4 release -
0ba23f9
chore: Preparing 3.0.6 release -
786c809
Fix: addressed a bypass on jsdom 22 when noframes tag is allowed -
5e24d1f
Merge pull request #815 from masatokinugawa/patch-1 -
1c9faab
Fixed a typo -
b958a25
fix: fixed a minor range issue on the demo website -
1245b40
Merge pull request #809 from cure53/dependabot/npm_and_yarn/socket.io-parser-... -
34141f1
build(deps): bump socket.io-parser from 4.2.1 to 4.2.3 - Additional commits viewable in compare view
Dependabot commands
You can trigger Dependabot actions by commenting on this MR
-
$dependabot rebase
will rebase this MR -
$dependabot recreate
will recreate this MR rewriting all the manual changes and resolving conflicts