Update dependency dompurify to v3.4.2
This MR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| dompurify | devDependencies | minor | 3.3.0 -> 3.4.2 |
MR created with the help of gitlab-org/frontend/renovate-gitlab-bot
Release Notes
cure53/DOMPurify (dompurify)
v3.4.2: DOMPurify 3.4.2
- Fixed an issue with URI validation on attributes allowed via
ADD_ATTRcallback, thanks @nelstrom - Fixed an issue with source maps referring to non-existing files, thanks @cmdcolin
- Updated existing workflows, fuzzer, release signing, etc., added more tests
- Bumped several dependencies where possible
v3.4.1: DOMPurify 3.4.1
- Fixed an issue with on-handler stripping for HTML-spec-reserved custom element names (
font-face,color-profile,missing-glyph,font-face-src,font-face-uri,font-face-format,font-face-name) under permissiveCUSTOM_ELEMENT_HANDLING - Fixed a case-sensitivity gap in the
annotation-xmlcheck that allowed mixed-case variants to bypass the basic-custom-element exclusion in XHTML mode - Fixed
SANITIZE_NAMED_PROPSrepeatedly prefixing already-prefixedidandnamevalues on subsequent sanitization - Fixed the
IN_PLACEroot-node check to explicitly guard against non-stringnodeName(DOM-clobbering robustness) - Removed a duplicate
slotentry from the default HTML attribute allow-list - Strengthened the fast-check fuzz harness with explicit XSS invariants, an expanded seed-payload corpus, an additional idempotence property for
SANITIZE_NAMED_PROPS, and a negative-control assertion ensuring the invariants actually fire - Added regression and pinning tests covering the above fixes and two accepted-behavior contracts (
SAFE_FOR_TEMPLATESgreedy scrub, hook-added attribute handling) - Extended CodeQL analysis to run on
3.xand2.xmaintenance branches
v3.4.0: DOMPurify 3.4.0
Most relevant changes:
- Fixed a problem with
FORBID_TAGSnot winning overADD_TAGS, thanks @kodareef5 - Fixed several minor problems and typos regarding MathML attributes, thanks @DavidOliver
- Fixed
ADD_ATTR/ADD_TAGSfunction leaking into subsequent array-based calls, thanks @1Jesper1 - Fixed a missing
SAFE_FOR_TEMPLATESscrub inRETURN_DOMpath, thanks @bencalif - Fixed a prototype pollution via
CUSTOM_ELEMENT_HANDLING, thanks @trace37labs - Fixed an issue with
ADD_TAGSfunction form bypassingFORBID_TAGS, thanks @eddieran - Fixed an issue with
ADD_ATTRpredicates skipping URI validation, thanks @christos-eth - Fixed an issue with
USE_PROFILESprototype pollution, thanks @christos-eth - Fixed an issue leading to possible mXSS via Re-Contextualization, thanks @researchatfluidattacks and others
- Fixed an issue with closing tags leading to possible mXSS, thanks @frevadiscor
- Fixed a problem with the type dentition patcher after Node version bump
- Fixed freezing BS runs by reducing the tested browsers array
- Bumped several dependencies where possible
- Added needed files for OpenSSF scorecard checks
Published Advisories are here: https://github.com/cure53/DOMPurify/security/advisories?state=published
v3.3.3: DOMPurify 3.3.3
- Fixed an engine requirement for Node 20 which caused hiccups, thanks @Rotzbua
v3.3.2: DOMPurify 3.3.2
- Fixed a possible bypass caused by jsdom's faulty raw-text tag parsing, thanks multiple reporters
- Fixed a prototype pollution issue when working with custom elements, thanks @christos-eth
- Fixed a lenient config parsing in
_isValidAttribute, thanks @christos-eth - Bumped and removed several dependencies, thanks @Rotzbua
- Fixed the test suite after bumping dependencies, thanks @Rotzbua
v3.3.1: DOMPurify 3.3.1
- Updated
ADD_FORBID_CONTENTSsetting to extend default list, thanks @MariusRumpf - Updated the ESM import syntax to be more correct, thanks @binhpv
Configuration
- If you want to rebase/retry this MR, check this box
This MR has been generated by Renovate Bot.