build(deps): bump dompurify from 3.1.5 to 3.2.5 in /modules/jooby-redoc
Merged
Number: #3671
Type: Pull Request
State: Merged
Type: Pull Request
State: Merged
Author:
dependabot[bot]
Association: Contributor
Comments: 0
Association: Contributor
Comments: 0
Created:
May 19, 2025 at 02:51 PM UTC
(about 1 year ago)
(about 1 year ago)
Updated:
May 19, 2025 at 03:16 PM UTC
(about 1 year ago)
(about 1 year ago)
Merged:
May 19, 2025 at 03:16 PM UTC
(about 1 year ago)
by jknack
(about 1 year ago)
by jknack
Time to Close:
24 minutes
Labels:
dependencies javascript
dependencies javascript
Description:
Bumps dompurify from 3.1.5 to 3.2.5.
Release notes
Sourced from dompurify's releases.
DOMPurify 3.2.5
- Added a check to the mXSS detection regex to be more strict, thanks
@masatokinugawa- Added ESM type imports in source, removes patch function, thanks
@donmccurdy- Added script to verify various TypeScript configurations, thanks
@reduckted- Added more modern browsers to the Karma launchers list
- Added Node 23.x to tested runtimes, removed Node 17.x
- Fixed the generation of source maps, thanks
@reduckted- Fixed an unexpected behavior with
ALLOWED_URI_REGEXPusing the 'g' flag, thanks@hhk-png- Fixed a few typos in the README file
DOMPurify 3.2.4
- Fixed a conditional and config dependent mXSS-style bypass reported by
@nsysean- Added a new feature to allow specific hook removal, thanks
@davecardwell- Added purify.js and purify.min.js to exports, thanks
@Aetherinox- Added better logic in case no window object is president, thanks
@yehuya- Updated some dependencies called out by dependabot
- Updated license files etc to show the correct year
DOMPurify 3.2.3
- Fixed two conditional sanitizer bypasses discovered by
@parrot409and@Slonser- Updated the attribute clobbering checks to prevent future bypasses, thanks
@parrot409DOMPurify 3.2.2
- Fixed a possible bypass in case a rather specific config for custom elements is set, thanks
@yaniv-git- Fixed several minor issues with the type definitions, thanks again
@reduckted- Fixed a minor issue with the types reference for trusted types, thanks
@reduckted- Fixed a minor problem with the template detection regex on some systems, thanks
@svdb99DOMPurify 3.2.1
- Fixed several minor issues with the type definitions, thanks
@reduckted@ghiscoding@asamuzaK@MiniDigger- Fixed an issue with non-minified dist files and order of imports, thanks
@reducktedDOMPurify 3.2.0
- Added type declarations, thanks
@reduckted,@philmayfield,@aloisklink,@ssi02014and others- Fixed a minor issue with the handling of hooks, thanks
@kevin-mizuDOMPurify 3.1.7
- Fixed an issue with comment detection and possible bypasses with specific config settings, thanks
@masatokinugawa- Fixed several smaller typos in documentation and test & build files, thanks
@christianhg- Added better support for Angular compiler, thanks
@jeroen1602- Added several new attributes to HTML and SVG allow-list, thanks
@Gigabyte5671and@Rotzbua- Removed the
foreignObjectelement from the list of HTML entry-points, thanks@masatokinugawa- Bumped several dependencies to be more up to date
DOMPurify 3.1.6
- Fixed an issue with the execution logic of attribute hooks to prevent bypasses, thanks
@kevin-mizu- Fixed an issue with element removal leading to uncaught errors through DOM Clobbering, thanks
@realansgar- Fixed a minor problem with the bower file pointing to the wrong dist path
- Fixed several minor typos in docs, comments and comment blocks, thanks
@Rotzbua- Updated several development dependencies
Commits
7806004Merge pull request #1082 from cure53/mainf14c22fchore: Preparing 3.2.5 releasec69d7a8Merge pull request #1080 from hhk-png/mainfce40b5chore: for lint59e8664Merge branch 'cure53:main' into maine62e3effix: Using ALLOWED_URI_REGEXP with the 'g' flag leads to incorrect resultsb428788Update README.md72c00dbMerge branch 'main' of github.com:cure53/DOMPurify49882dctest: Added Node 23.x to tested runtimes, removed Node 17.x2e5fd64Merge pull request #1078 from reduckted/fix-sourcemaps- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the Security Alerts page.
Pull Request Statistics
Commits:
1
1
Files Changed:
1
1
Additions:
+14
+14
Deletions:
-3
-3
Package Dependencies
Package:
dompurify
Ecosystem:
npm
npm
Version Change:
3.1.5 → 3.2.5
Update Type:
Minor
Minor
Path:
/modules/jooby-redoc
Technical Details
| ID: | 470558 |
| UUID: | 2528981984 |
| Node ID: | PR_kwDOAYRJs86WvTPg |
| Host: | GitHub |
| Repository: | jooby-project/jooby |
| Merge State: | Unknown |