Build(deps): bump league/commonmark from 2.6.1 to 2.7.0 in the composer group
Type: Pull Request
State: Merged
Association: Contributor
Comments: 0
(7 months ago)
(6 months ago)
(6 months ago)
by CrazyBoy49z
dependencies php
Bumps the composer group with 1 update: league/commonmark.
Updates league/commonmark from 2.6.1 to 2.7.0
Release notes
Sourced from league/commonmark's releases.
2.7.0
This is a security release to address a potential cross-site scripting (XSS) vulnerability when using the
AttributesExtensionwith untrusted user input.Added
- Added
attributes/allowconfig option to specify which attributes users are allowed to set on elements (default allows virtually all attributes)Changed
- The
AttributesExtensionblocks all attributes starting withonunless explicitly allowed via theattributes/allowconfig option- The
allow_unsafe_linksoption is now respected by theAttributesExtensionwhen users specifyhrefandsrcattributes2.6.2
Fixed
- Fixed Attributes extension parsing regression (#1071)
Other Changes
- fix incorrect interface in docs v2.6 by
@CharrafiMedin thephpleague/commonmark#1063- docs/2.6/extensions/front-matter.md: add missing newline by
@DanielEScherzerin thephpleague/commonmark#1069New Contributors
@CharrafiMedmade their first contribution in thephpleague/commonmark#1063@DanielEScherzermade their first contribution in thephpleague/commonmark#1069Full Changelog: https://github.com/thephpleague/commonmark/compare/2.6.1...2.6.2
Changelog
Sourced from league/commonmark's changelog.
[2.7.0]
This is a security release to address a potential cross-site scripting (XSS) vulnerability when using the
AttributesExtensionwith untrusted user input.Added
- Added
attributes/allowconfig option to specify which attributes users are allowed to set on elements (default allows virtually all attributes)Changed
- The
AttributesExtensionblocks all attributes starting withonunless explicitly allowed via theattributes/allowconfig option- The
allow_unsafe_linksoption is now respected by theAttributesExtensionwhen users specifyhrefandsrcattributes[2.6.2] - 2025-04-18
Fixed
- Fixed Attributes extension parsing regression (#1071)
Commits
6fbb36dPrepare to release 2.7.0f0d626cMerge commit from fork4320725Fix XSS in AttributesExtensiond4b08b8Create 2.7 branch5b794e1Remove docs for 1.0 - 1.53db9d35Merge branch '2.6'06c3b0bPrepare to release 2.6.2771974cFix Attributes extension parsing regression (#1071)e99ee2eMerge pull request #1069 from DanielEScherzer/patch-1f356ca5docs/2.6/extensions/front-matter.md: add missing newline- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions
You can disable automated security fix PRs for this repo from the Security Alerts page.
Pull Request Statistics
1
1
+18
-18
Package Dependencies
league/commonmark
packagist
2.6.1 → 2.7.0
Minor
the composer group
Technical Details
| ID: | 750218 |
| UUID: | 2500195652 |
| Node ID: | PR_kwDOKL5X8s6VBfVE |
| Host: | GitHub |
| Repository: | step2dev/lazy-ui-docs |
| Merge State: | Unknown |