Bump league/commonmark from 2.6.2 to 2.7.0 in /drupal
Bumps league/commonmark from 2.6.2 to 2.7.0.
Release notes
Sourced from league/commonmark's releases.
2.7.0
This is a security release to address a potential cross-site scripting (XSS) vulnerability when using the
AttributesExtensionwith untrusted user input.Added
- Added
attributes/allowconfig option to specify which attributes users are allowed to set on elements (default allows virtually all attributes)Changed
- The
AttributesExtensionblocks all attributes starting withonunless explicitly allowed via theattributes/allowconfig option- The
allow_unsafe_linksoption is now respected by theAttributesExtensionwhen users specifyhrefandsrcattributes
Changelog
Sourced from league/commonmark's changelog.
[2.7.0]
This is a security release to address a potential cross-site scripting (XSS) vulnerability when using the
AttributesExtensionwith untrusted user input.Added
- Added
attributes/allowconfig option to specify which attributes users are allowed to set on elements (default allows virtually all attributes)Changed
- The
AttributesExtensionblocks all attributes starting withonunless explicitly allowed via theattributes/allowconfig option- The
allow_unsafe_linksoption is now respected by theAttributesExtensionwhen users specifyhrefandsrcattributes
Commits
6fbb36dPrepare to release 2.7.0f0d626cMerge commit from fork4320725Fix XSS in AttributesExtensiond4b08b8Create 2.7 branch5b794e1Remove docs for 1.0 - 1.53db9d35Merge branch '2.6'01ad002Merge pull request #1066 from elazar/front-matter-missing-newlinede872baAdd missing newline in Front Matter exampledfe07dbMerge remote-tracking branch 'origin/2.6'88365ecFix doc version issues- See full diff in compare view
You can trigger a rebase of this PR by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency -
@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.
Note Automatic rebases have been disabled on this pull request as it has been open for over 30 days.
Codecov Report
All modified and coverable lines are covered by tests :white_check_mark:
Project coverage is 26.69%. Comparing base (
84041d7) to head (b0a2bd6). Report is 18 commits behind head on master.
Additional details and impacted files
@@ Coverage Diff @@
## master #2677 +/- ##
=======================================
Coverage 26.69% 26.69%
=======================================
Files 42 42
Lines 5901 5901
Branches 37 37
=======================================
Hits 1575 1575
Misses 4326 4326
| Flag | Coverage Δ | |
|---|---|---|
| cdk | 96.59% <ø> (ø) |
Flags with carried forward coverage won't be shown. Click here to find out more.
:umbrella: View full report in Codecov by Sentry.
:loudspeaker: Have feedback on the report? Share it here.
:rocket: New features to boost your workflow:
- :snowflake: Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
- :package: JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.
opendata
Run #5489
Run Properties:
Passed #5489 •
c55b0515ac ℹ️: Merge b0a2bd6af6e3ab07e699599c744e6702b9c170fa into 5bdf8f78c15699f29fa3ae876289...
| Project |
opendata
|
| Branch Review |
dependabot/composer/drupal/league/commonmark-2.7.0
|
| Run status |
|
| Run duration | 03m 55s |
| Commit |
|
| Committer | dependabot[bot] |
| View all properties for this run ↗︎ | |
| Test results | |
|---|---|
|
|
0
|
|
|
0
|
|
|
2
|
|
|
0
|
|
|
83
|
| View all changes introduced in this branch ↗︎ | |