code-tours-github
code-tours-github copied to clipboard
Bump xss from 1.0.9 to 1.0.14
trafficstars
Bumps xss from 1.0.9 to 1.0.14.
Changelog
Sourced from xss's changelog.
v1.0.14 (2022-08-16)
v1.0.13 (2022-06-07)
v1.0.12 (2022-06-04)
- feat: add eslint:recommended check by
@lumburr- fix: comment has encoded by
@lumburr- fix: whitelist match failure due to case ignoring by
@lumburr- fix: class is wrong separated by attributes in method onTagAttr by
@lumburrv1.0.11 (2022-03-06)
v1.0.10 (2021-10-08)
- [Fix: #239 stripCommentTag DoS attack](leizongmin/js-xss#239)
Commits
c339c1fpublish: v1.0.1471c3f25fix: add allowList to types (#261)72844ddfix: problem with not closed tag (#262)c2419c4publish: v1.0.13352ae53Revert "fix: comment has encoded (#257)"76d87aapublish: v1.0.122e8e8cechore: update devDependenciesd7654e5fix: usevarinstead ofletc536c0dfix: problem with backslash and space at the beginning of attribute value (#253)1e44466fix: whitelist match failure due to case ignoring (#256)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)