AltspaceSDK
AltspaceSDK copied to clipboard
Bump postcss and sanitize-html
Bumps postcss and sanitize-html. These dependencies needed to be updated together.
Updates postcss
from 6.0.19 to 7.0.39
Release notes
Sourced from postcss's releases.
7.0.39
- Reduce package size.
- Backport
nanocolors
topicocolors
migration.7.0.38
- Update
Processor#version
.7.0.37
- Backport
chalk
tonanocolors
migration.7.0.36
- Backport ReDoS vulnerabilities from PostCSS 8.
7.0.35
- Add migration guide link to PostCSS 8 error text.
7.0.34
- Fix compatibility with
postcss-scss
2.7.0.33
- Add error message for PostCSS 8 plugins.
7.0.32
- Fix error message (by
@admosity
).7.0.31
- Use only the latest source map annotation (by
@emzoumpo
).7.0.30
- Fix TypeScript definition (by
@nex3
)7.0.29
- Update
Processor#version
.7.0.28
- Fix TypeScript definition (by
@nex3
).7.0.27
- Fix TypeScript definition (by
@nex3
).7.0.26
- Fix TypeScript definition (by
@nex3
)7.0.25
- Fix absolute path support for Windows (by
@tomrav
)7.0.24
- Fix TypeScript definition (by
@keithamus
).7.0.23
... (truncated)
Changelog
Sourced from postcss's changelog.
7.0.39
- Reduce package size.
- Backport
nanocolors
topicocolors
migration.7.0.38
- Update
Processor#version
.7.0.37
- Backport
chalk
tonanocolors
migration.7.0.36
- Backport ReDoS vulnerabilities from PostCSS 8.
7.0.35
- Add migration guide link to PostCSS 8 error text.
7.0.34
- Fix compatibility with
postcss-scss
2.7.0.33
- Add error message for PostCSS 8 plugins.
7.0.32
- Fix error message (by
@admosity
).7.0.31
- Use only the latest source map annotation (by Emmanouil Zoumpoulakis).
7.0.30
- Fix TypeScript definition (by Natalie Weizenbaum).
7.0.29
- Update
Processor#version
.7.0.28
- Fix TypeScript definition (by Natalie Weizenbaum).
7.0.27
- Fix TypeScript definition (by Natalie Weizenbaum).
7.0.26
- Fix TypeScript definition (by Natalie Weizenbaum).
7.0.25
- Fix absolute path support for Windows (by Tom Raviv).
7.0.24
- Fix TypeScript definition (by Keith Cirkel).
7.0.23
... (truncated)
Commits
e17c1ef
Release 7.0.39 version6791bd3
Reduce npm package44c581a
Replace nanocolors with picocolors8ba21fd
Remove eslint-ci3994c4a
Release 7.0.38 version6944e1d
Remove development keys from package.json4dd0af0
Release 7.0.37 version8408eb4
Add compilation step0c68063
Move tests to GitHub Actions98b61ba
Replace chalk to nanocolors- Additional commits viewable in compare view
Updates sanitize-html
from 1.18.2 to 1.27.5
Changelog
Sourced from sanitize-html's changelog.
1.27.5 (2020-09-23):
- Updates README to include ES modules syntax.
1.27.4 (2020-08-26):
- Fixes an IE11 regression from using
Array.prototype.includes
, replacing it withArray.prototype.indexOf
.1.27.3 (2020-08-12):
- Fixes a bug when using
transformTags
with outtextFilter
. Thanks to Andrzej Porebski for the help with a failing test.1.27.2 (2020-07-29):
- Fixes CHANGELOG links. Thanks to Alex Mayer for the contribution.
- Replaces
srcset
withparse-srcset
. Thanks to Massimiliano Mirra for the contribution.1.27.1 (2020-07-15):
- Removes the unused chalk dependency.
- Adds configuration for a Github stale bot.
- Replace
xtend
package with nativeObject.assign
.1.27.0:
- Adds the
allowedIframeDomains
option. This works similar toallowedIframeHostnames
, where you would set it to an array of web domains. It would then permit any hostname on those domains to be used in iframesrc
attributes. Thanks to Stanislav Kravchenko for the contribution.1.26.0:
- Adds the
option
element to the defaultnonTextTagsArray
of tags with contents that aren't meant to be displayed visually as text. This can be overridden with thenonTextTags
option.1.25.0:
- Adds
enforceHtmlBoundary
option to process code bounded by thehtml
tag, discarding any code outside of those tags.- Migrates to the main lodash package from the per method packages since they are deprecated and cause code duplication. Thanks to Merceyz for the contribution.
- Adds a warning when
style
andscript
tags are allowed, as they are inherently vulnerable to being used in XSS attacks. That warning can be disabled by including the optionallowVulnerableTags: true
so this choice is knowing and explicit.1.24.0:
- Fixes a bug where self-closing tags resulted in deletion with
disallowedTagsMode: 'escape'
set. Thanks to Thiago Negri for the contribution.- Adds
abbr
to the defaultallowedTags
for better accessibility support. Thanks to Will Farrell for the contribution.- Adds a
mediaChildren
property to theframe
object in custom filters. This allows you to check for links or other parent tags that contain self-contained media to prevent collapse, regardless of whether there is also text inside. Thanks to axdg for the initial implementation and Marco Arduini for a failing test contribution.1.23.0:
- Adds eslint configuration and adds eslint to test script.
- Sets
sideEffects: false
on package.json to allow module bundlers like webpack tree-shake this module and all the dependencies from client build. Thanks to Egor Voronov for the contribution.- Adds the
tagName
(HTML element name) as a second parameter passed totextFilter
. Thanks to Slava for the contribution.1.22.1:
ncreases the patch version of
lodash.mergewith
to enforce an audit fix.1.22.0:
bumped
htmlparser2
dependency to the 4.x series. This fixes longstanding bugs and should cause no bc breaks for this module, since the only bc breaks upstream are in regard to features we don't expose in this module.1.21.1:
fixed issue with bad
main
setting in package.json that broke 1.21.0.1.21.0:
new
disallowedTagsMode
option can be set toescape
to escape disallowed tags rather than discarding them. Any subtags are handled as usual. If you want to recursively escape them too, you can setdisallowedTagsMode
torecursiveEscape
. Thanks to Yehonatan Zecharia for this contribution.
... (truncated)
Commits
- See full diff in compare view
Maintainer changes
This version was pushed to npm by alexbea, a new releaser for sanitize-html since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.