Skip to content

Conversation

XTechnology-TR
Copy link
Owner

snyk-top-banner

Snyk has created this PR to upgrade dompurify from 2.3.1 to 2.5.7.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 29 versions ahead of your current version.

  • The recommended version was released on 2 months ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Prototype Pollution
SNYK-JS-DOMPURIFY-7984421
89 No Known Exploit
medium severity Template Injection
SNYK-JS-DOMPURIFY-6474511
89 Proof of Concept
medium severity Cross-site Scripting (XSS)
SNYK-JS-DOMPURIFY-8184974
89 Proof of Concept
critical severity Prototype Pollution
SNYK-JS-DOMPURIFY-8318045
89 No Known Exploit
Release notes
Package name: dompurify
  • 2.5.7 - 2024-09-26
    • Fixed an issue with comment detection and possible bypasses with specific config settings, thanks @ masatokinugawa
    • Removed the foreignObject element from the list of HTML entry-points, thanks @ masatokinugawa
  • 2.5.6 - 2024-07-05
    • Fixed an issue with the execution logic of attribute hooks to prevent bypasses, thanks @ kevin-mizu
    • Fixed a minor problem with the bower file pointing to the wrong dist path
    • Updated several development dependencies
  • 2.5.5 - 2024-05-31
    • Fixed a minor issue with the dist paths in bower.js, thanks @ HakumenNC
    • Fixed a minor issue with sanitizing HTML coming from copy&paste Word content, thanks @ kakao-bishop-cho
  • 2.5.4 - 2024-05-20
    • Fixed a bug with latest isNaN checks affecting MSIE, thanks @ tulach
    • Fixed the tests for MSIE and fixed related test-runner
  • 2.5.3 - 2024-05-11
  • 2.5.2 - 2024-04-30
  • 2.5.1 - 2024-04-26
  • 2.5.0 - 2024-04-07
  • 2.4.9 - 2024-03-21
  • 2.4.8 - 2024-03-19
  • 2.4.7 - 2023-07-11
  • 2.4.6 - 2023-07-10
  • 2.4.5 - 2023-03-01
  • 2.4.4 - 2023-02-13
  • 2.4.3 - 2023-01-06
  • 2.4.2 - 2023-01-05
  • 2.4.1 - 2022-11-10
  • 2.4.0 - 2022-08-24
  • 2.3.12 - 2022-08-23
  • 2.3.11 - 2022-08-23
  • 2.3.10 - 2022-07-18
  • 2.3.9 - 2022-07-11
  • 2.3.8 - 2022-05-13
  • 2.3.7 - 2022-05-11
  • 2.3.6 - 2022-02-16
  • 2.3.5 - 2022-01-26
  • 2.3.4 - 2021-12-07
  • 2.3.3 - 2021-09-20
  • 2.3.2 - 2021-09-15
  • 2.3.1 - 2021-08-13
from dompurify GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade dompurify from 2.3.1 to 2.5.7. See this package in npm: dompurify See this project in Snyk: https://app.snyk.io/org/xtechnology-tr/project/87f222e9-6455-42ce-b1bd-e7b3fba21a79?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

2 participants