Skip to content

[Snyk] Security upgrade dompurify from 1.0.8 to 2.0.17#14

Open
snyk-bot wants to merge 1 commit intomasterfrom
snyk-fix-4a6048112df3c68cc1537395ec731987
Open

[Snyk] Security upgrade dompurify from 1.0.8 to 2.0.17#14
snyk-bot wants to merge 1 commit intomasterfrom
snyk-fix-4a6048112df3c68cc1537395ec731987

Conversation

@snyk-bot
Copy link

@snyk-bot snyk-bot commented Oct 9, 2020

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 673/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.6
Cross-site Scripting (XSS)
SNYK-JS-DOMPURIFY-1016634
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: dompurify The new version differs by 250 commits.
  • f04574b chore: preparing 2.0.17 release
  • 02724b8 fix: attemtping to fix another mutation behavior
  • 63061bf chore: Preparing 2.0.16 release
  • 95b7ad2 See #470
  • ce22c8c fix: Attempting to fix a MathML-based mXSS pattern
  • c025bc8 chore: preparing 2.0.15 release
  • 10ed33f fix: changed the linter settings to be more tolerant
  • 5922db6 Merge branch 'main' of git@github.com:cure53/DOMPurify.git into main
  • 7f6dfe2 docs: added peernohell to list of contributors
  • 4743c0b Merge pull request #464 from peernohell/main
  • 1727266 add VirtualConsole to hide jsdom warning
  • 65523f7 update yarn.lock file
  • eca5522 Merge branch 'main' of https://github.com/cure53/DOMPurify into main
  • a0499ba Update jsdom to version 16.x.x
  • e2b2a09 test: fixed a test for Edge 17
  • 340ec35 chore: testing CodeQL workflow
  • 969cbef Merge pull request #463 from timgates42/bugfix_typo_return
  • aa82f71 docs: Fix simple typo, retrun -> return
  • 43530e9 docs: extended README with better documentation examples
  • 1b1b9ea chore: added more badges to website because badges
  • f26f3d8 fix: attempting to fix a prototype pollution targeting SAFE_FOR_JQUERY
  • 77a7fe7 fix: fixed a problem with documentMode default
  • 7491db1 chore: preparing 2.0.13 release
  • fd520c6 fix: fixed a broken test affecting older browsers

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant