create-wordpress-plugin
create-wordpress-plugin copied to clipboard
Bump dompurify from 3.1.5 to 3.1.7
Bumps dompurify from 3.1.5 to 3.1.7.
Release notes
Sourced from dompurify's releases.
DOMPurify 3.1.7
- Fixed an issue with comment detection and possible bypasses with specific config settings, thanks
@masatokinugawa- Fixed several smaller typos in documentation and test & build files, thanks
@christianhg- Added better support for Angular compiler, thanks
@jeroen1602- Added several new attributes to HTML and SVG allow-list, thanks
@Gigabyte5671and@Rotzbua- Removed the
foreignObjectelement from the list of HTML entry-points, thanks@masatokinugawa- Bumped several dependencies to be more up to date
DOMPurify 3.1.6
- Fixed an issue with the execution logic of attribute hooks to prevent bypasses, thanks
@kevin-mizu- Fixed an issue with element removal leading to uncaught errors through DOM Clobbering, thanks
@realansgar- Fixed a minor problem with the bower file pointing to the wrong dist path
- Fixed several minor typos in docs, comments and comment blocks, thanks
@Rotzbua- Updated several development dependencies
Commits
69c8c12Merge pull request #999 from cure53/main15f54edchore: Regenerated source maps4f3b5cbMerge pull request #998 from cure53/main50aec03chore: Preparing 3.1.7 release4a9ec1ffix: Fixed an issue with comment detection and possible bypasses with specifi...50ea515Merge pull request #993 from cure53/dependabot/npm_and_yarn/body-parser-1.20.3b6188ecbuild(deps): bump body-parser from 1.20.1 to 1.20.31e2cb9bMerge pull request #990 from jeroen1602/angular_support745b521Added support for the Angular compiler.c1949fbMerge pull request #989 from cure53/dependabot/npm_and_yarn/webpack-5.94.0- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)