code-tours-github
code-tours-github copied to clipboard
Bump xss from 1.0.9 to 1.0.14
Bumps xss from 1.0.9 to 1.0.14.
Changelog
Sourced from xss's changelog.
v1.0.14 (2022-08-16)
v1.0.13 (2022-06-07)
v1.0.12 (2022-06-04)
- feat: add eslint:recommended check by
@lumburr
- fix: comment has encoded by
@lumburr
- fix: whitelist match failure due to case ignoring by
@lumburr
- fix: class is wrong separated by attributes in method onTagAttr by
@lumburr
v1.0.11 (2022-03-06)
v1.0.10 (2021-10-08)
- [Fix: #239 stripCommentTag DoS attack](leizongmin/js-xss#239)
Commits
c339c1f
publish: v1.0.1471c3f25
fix: add allowList to types (#261)72844dd
fix: problem with not closed tag (#262)c2419c4
publish: v1.0.13352ae53
Revert "fix: comment has encoded (#257)"76d87aa
publish: v1.0.122e8e8ce
chore: update devDependenciesd7654e5
fix: usevar
instead oflet
c536c0d
fix: problem with backslash and space at the beginning of attribute value (#253)1e44466
fix: whitelist match failure due to case ignoring (#256)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)