Bump dompurify from 2.4.4 to 3.1.1
Bumps dompurify from 2.4.4 to 3.1.1.
Release notes
Sourced from dompurify's releases.
DOMPurify 3.1.1
- Fixed an mXSS sanitiser bypass reported by
@icesfont
- Added new code to track element nesting depth
- Added new code to enforce a maximum nesting depth of 255
- Added coverage tests and necessary clobbering protections
Note that this is a security release and should be upgraded to immediately. Please also note that further releases may follow as the underlying vulnerability is apparently new and further variations may be discovered.
DOMPurify 3.1.0
- Added new setting
SAFE_FOR_XML
to enable better control over comment scrubbing- Updated README to warn about happy-dom not being safe for use with DOMPurify yet
- Updated the LICENSE file to show the accurate year number
- Updated several build and test dependencies
DOMPurify 3.0.11
- Fixed another conditional bypass caused by Processing Instructions, thanks
@Ry0taK
- Fixed the regex for HTML Custom Element detection, thanks
@AlekseySolovey3T
DOMPurify 3.0.10
- Fixed two possible bypasses when sanitizing an XML document and later using it in HTML, thanks
@Slonser
- Bumped up some build and test dependencies
DOMPurify 3.0.9
- Fixed a problem with proper detection of Custom Elements, thanks
@kevin-mizu
- Refactored the
hasOwnProperty
logic, thanks@ssi02014
- Removed a superfluous
console.warn
making HappyDom happier, thanks@HugoPoi
- Modernized some of the demo hooks for better looks, thanks
@Steb95
DOMPurify 3.0.8
- Fixed errors caused by conditional exports, thanks
@ssi02014
- Fixed a type error when working with custom element config, thanks
@cpmotion
DOMPurify 3.0.7
- Added better protection against CSPP attacks, thanks
@kevin-mizu
- Updated browser versions for automated tests
- Updated Node versions for automated tests
- Refactored code base, thanks
@ssi02014
- Refactored build system & deployment, thanks
@ssi02014
DOMPurify 3.0.6
- Refactored the core code-base and several utilities, thanks
@ssi02014
- Updated and fixed several sections of the README, thanks
@ssi02014
- Updated several outdated build and test dependencies
DOMPurify 3.0.5
- Fixed a licensing issue spotted and reported by
@george-thomas-hill
- Updated several build and test dependencies
DOMPurify 3.0.4
- Fixed a bypass in jsdom 22 in case the noframes element is permitted, thanks
@leeN
... (truncated)
Commits
-
7a0a984
Merge pull request #944 from cure53/main -
7bbd12b
chore: Preparing 3.1.1 release -
87eff29
Merge branch 'main' of github.com:cure53/DOMPurify -
809a902
fix: Set the MAX_NESTING_DEPTH to 255 for good measure and adjusted tests -
6ea80cd
Merge pull request #943 from cure53/main -
c0d418c
Merge pull request #942 from kyselberg/main -
2a554b4
docs: additional info in example -
6e240ec
docs: correct hook name and remove misleading comment -
ef4bbb4
chore: Re-generated dist versions -
1f494b9
Merge pull request #941 from icesfont/fix/deep-nesting-mxss - Additional commits viewable in compare view
Dependabot commands
You can trigger Dependabot actions by commenting on this MR
-
$dependabot rebase
will rebase this MR -
$dependabot recreate
will recreate this MR rewriting all the manual changes and resolving conflicts