xbuilder-server
xbuilder-server copied to clipboard
Bump dompurify from 2.0.12 to 2.2.6 in /docusaurus
Bumps dompurify from 2.0.12 to 2.2.6.
Release notes
Sourced from dompurify's releases.
DOMPurify 2.2.6
- Added new mXSS prevention logic created by SecurityMB
DOMPurify 2.2.4
- Fixed a new MathML-based bypass submitted by PewGrand
- Fixed a new SVG-related bypass submitted by SecurityMB
- Updated NodeJS CI to Node 14.x and Node 15.x
- Cleaned up
_forceRemovelogic for better reliabilityDOMPurify 2.2.3
- Fixed an mXSS issue reported by PewGrand
- Fixed a minor issue with the license header
- Fixed a problem with overly-eager CSS stripping
- Updated the README and removed an XSS warning
DOMPurify 2.2.2
- Fixed an mXSS bypass dropped on us publicly via #482
- Fixed an mXSS variation that was reported privately short after
- Added dialog to permitted elements list
- Fixed a small typo in the README
DOMPurify 2.2.0
- Fix a possible XSS in Chrome that is hidden behind #enable-experimental-web-platform-features, reported by @neilj and @mfreed7
- Changed
RETURN_DOM_IMPORTdefault totrueto address said possible XSS- Updated README to reflect the new change and inform about the risks of manually setting
RETURN_DOM_IMPORTback tofalse- Fixed the tests to properly address the new default
DOMPurify 2.1.1
- Removed some code targeting old Safari versions
- Removed some code targeting older MS Edge versions
- Re-added some code targeting older Chrome versions, thanks @terjanq
- Added new tests and removed unused SAFE_FOR_JQUERY test cases
- Added Node 14.x to existing test coverage
DOMPurify 2.1.0
- Fixed several possible mXSS patterns, thanks @hackvertor
- Removed the
SAFE_FOR_JQUERYflag (we are safe by default now for jQuery)- Removed several now useless mXSS checks
- Updated the mXSS check for elements
- Updated test cases to cover new sanitization strategy
- Updated test website to use newer jQuery
- Updated array of tested browsers and removed legacy browsers
- Added "auto convert" checkbox to test website, thanks @hackvertor
DOMPurify 2.0.17
- Fixed another bypass causing mXSS by using MathML
DOMPurify 2.0.16
- Fixed an mXSS-based bypass caused by nested forms inside MathML
- Fixed a security error thrown on older Chrome on Android versions, see #470
... (truncated)
Commits
b11cb72chore: Preparing 2.2.6 release after failed 2.2.5 attempt /2395cc83chore: Preparing 2.2.6 release after failed 2.2.5 attempt8a1c887chore: Preparing 2.2.5 release77e740eMerge pull request #496 from securityMB/main9dd47cbCreate a polyfill for lookupGetter to make IE10 happy8e29990fix: Made use of proper helper method to get parentNode7e3a705fix: Fixed an issue with parent node mapping in MSIE11d1cf8c6test: Fixed additional Edge 17 and MSIE11 tests1446372test: Fixed a bunch of Edge 17 and MSIE11 tests7d9bc6afix: Removed usage of has()- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)@dependabot use these labelswill set the current labels as the default for future PRs for this repo and language@dependabot use these reviewerswill set the current reviewers as the default for future PRs for this repo and language@dependabot use these assigneeswill set the current assignees as the default for future PRs for this repo and language@dependabot use this milestonewill set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the Security Alerts page.