chore(deps): bump dompurify from 3.3.1 to 3.3.3
Open
Number: #8366
Type: Pull Request
State: Open
Type: Pull Request
State: Open
Author:
dependabot[bot]
Association: Unknown
Comments: 4
Association: Unknown
Comments: 4
Created:
March 28, 2026 at 10:25 AM UTC
(3 months ago)
(3 months ago)
Updated:
April 14, 2026 at 09:41 PM UTC
(2 months ago)
(2 months ago)
Labels:
dependencies javascript
dependencies javascript
Description:
Bumps dompurify from 3.3.1 to 3.3.3.
Release notes
Sourced from dompurify's releases.
DOMPurify 3.3.3
- Fixed an engine requirement for Node 20 which caused hiccups, thanks
@RotzbuaDOMPurify 3.3.2
- Fixed a possible bypass caused by jsdom's faulty raw-text tag parsing, thanks multiple reporters
- Fixed a prototype pollution issue when working with custom elements, thanks
@christos-eth- Fixed a lenient config parsing in
_isValidAttribute, thanks@christos-eth- Bumped and removed several dependencies, thanks
@Rotzbua- Fixed the test suite after bumping dependencies, thanks
@Rotzbua
Commits
8bcbf73chore: Preparing 3.3.3 release5faddd6fix: engine requirement (#1210)0f91e3aUpdate README.mdd5ff1a8Merge branch 'main' of github.com:cure53/DOMPurifyc3efd48fix: moved back from jsdom 28 to jsdom 20988b888fix: moved back from jsdom 28 to jsdom 202726c74chore: Preparing 3.3.2 release6202c7ebuild(deps): bump@tootallnate/onceand jsdom (#1204)302b51dfix: Expanded the regex ever so slightly to also cover scriptcd85175Merge branch 'main' of github.com:cure53/DOMPurify- Additional commits viewable in compare view
Package Dependencies
Technical Details
| ID: | 15310991 |
| UUID: | 4159185613 |
| Node ID: | PR_kwDOATMJfM7OQnJO |
| Host: | GitHub |
| Repository: | BitGo/BitGoJS |