[Snyk] Upgrade dompurify from 3.1.7 to 3.2.6 #175
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade dompurify from 3.1.7 to 3.2.6.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version is 7 versions ahead of your current version.
The recommended version was released 3 months ago.
Issues fixed by the recommended upgrade:
SNYK-JS-DOMPURIFY-8722251
Release notes
Package name: dompurify
-
3.2.6 - 2025-05-19
- Fixed several typos and removed clutter from our documentation, thanks @ Rotzbua
- Added
- Added better config hardening against prototype pollution, thanks @ EffectRenan
- Added better handling of attribute removal, thanks @ michalnieruchalski-tiugo
- Added better configuration for aggressive mXSS scrubbing behavior, thanks @ BryanValverdeU
- Removed the script that caused the fake entry CVE-2025-48050
-
3.2.5 - 2025-04-03
- Added a check to the mXSS detection regex to be more strict, thanks @ masatokinugawa
- Added ESM type imports in source, removes patch function, thanks @ donmccurdy
- Added script to verify various TypeScript configurations, thanks @ reduckted
- Added more modern browsers to the Karma launchers list
- Added Node 23.x to tested runtimes, removed Node 17.x
- Fixed the generation of source maps, thanks @ reduckted
- Fixed an unexpected behavior with
- Fixed a few typos in the README file
-
3.2.4 - 2025-01-30
- Fixed a conditional and config dependent mXSS-style bypass reported by @ nsysean
- Added a new feature to allow specific hook removal, thanks @ davecardwell
- Added purify.js and purify.min.js to exports, thanks @ Aetherinox
- Added better logic in case no window object is president, thanks @ yehuya
- Updated some dependencies called out by dependabot
- Updated license files etc to show the correct year
-
3.2.3 - 2024-12-09
- Fixed two conditional sanitizer bypasses discovered by @ parrot409 and @ Slonser
- Updated the attribute clobbering checks to prevent future bypasses, thanks @ parrot409
-
3.2.2 - 2024-11-29
- Fixed a possible bypass in case a rather specific config for custom elements is set, thanks @ Yaniv-git
- Fixed several minor issues with the type definitions, thanks again @ reduckted
- Fixed a minor issue with the types reference for trusted types, thanks @ reduckted
- Fixed a minor problem with the template detection regex on some systems, thanks @ svdb99
-
3.2.1 - 2024-11-20
- Fixed several minor issues with the type definitions, thanks @ reduckted @ ghiscoding @ asamuzaK @ MiniDigger
- Fixed an issue with non-minified dist files and order of imports, thanks @ reduckted
-
3.2.0 - 2024-11-11
- Added type declarations, thanks @ reduckted , @ philmayfield, @ aloisklink, @ ssi02014 and others
- Fixed a minor issue with the handling of hooks, thanks @ kevin-mizu
-
3.1.7 - 2024-09-26
- Fixed an issue with comment detection and possible bypasses with specific config settings, thanks @ masatokinugawa
- Fixed several smaller typos in documentation and test & build files, thanks @ christianhg
- Added better support for Angular compiler, thanks @ jeroen1602
- Added several new attributes to HTML and SVG allow-list, thanks @ Gigabyte5671 and @ Rotzbua
- Removed the
- Bumped several dependencies to be more up to date
from dompurify GitHub release notesmatrix:as an allowed URI scheme, thanks @ kleinesfilmroellchenALLOWED_URI_REGEXPusing the 'g' flag, thanks @ hhk-pngforeignObjectelement from the list of HTML entry-points, thanks @ masatokinugawaImportant
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information: