Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade dompurify from 3.0.5 to 3.0.6 #204

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

victorDigital
Copy link
Member

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade dompurify from 3.0.5 to 3.0.6.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 1 version ahead of your current version.
  • The recommended version was released a month ago, on 2023-09-28.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Use of Weak Hash
SNYK-JS-CRYPTOES-6032390
716/1000
Why? Recently disclosed, Has a fix available, CVSS 8.6
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: dompurify
  • 3.0.6 - 2023-09-28
    • Refactored the core code-base and several utilities, thanks @ ssi02014
    • Updated and fixed several sections of the README, thanks @ ssi02014
    • Updated several outdated build and test dependencies
  • 3.0.5 - 2023-07-11
    • Fixed a licensing issue spotted and reported by @ george-thomas-hill
    • Updated several build and test dependencies
from dompurify GitHub release notes
Commit messages
Package name: dompurify
  • 1b864e7 Merge pull request #860 from cure53/main
  • 7e6a7ee chore: Preparing 3.0.6 release
  • 7718a39 Update README.md
  • 1b76e6c Update README.md
  • 977df97 Update README.md
  • 926a8cd Merge pull request #855 from cure53/dependabot/github_actions/actions/checkout-4
  • 2d1a4c3 build(deps): bump actions/checkout from 3 to 4
  • 48bd850 docs: Fixed a faulty sanitization result in README
  • 1154de2 Merge pull request #850 from ssi02014/fix/createIterator
  • e79525c refac(purify): Rename _isBasicCustomElement
  • 945fd1d refac(purify): Rename _isBasicCustomElementCheck
  • 5d0c441 fix(purify): fix test error
  • 394a6d0 fix(purify): fix createIterator
  • a608d4f fix(purify): fix createIterator
  • cba5757 docs: updated contributor list
  • 2b012d2 Merge pull request #849 from ssi02014/refac/purify
  • 37abb76 refac(purify): Refactoring purify
  • 59c7807 Merge pull request #848 from ssi02014/fix/purify
  • 68ad9a9 fix(purify): Remove unnecessary conditional expressions
  • d5060b3 Merge pull request #845 from ssi02014/fix/purify
  • 25b1b21 revert(purify): revert isNode Functio Name
  • 5f12c81 refac(purify): Initialize content null
  • 276bedb fix(purify): Fix _isNode function
  • 84508da fix(purify): Fix _isNode function

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

@netlify
Copy link

netlify bot commented Oct 28, 2023

Deploy Preview for betlec ready!

Name Link
🔨 Latest commit 7a6afa0
🔍 Latest deploy log https://app.netlify.com/sites/betlec/deploys/653c73eac83d4d0007c933c3
😎 Deploy Preview https://deploy-preview-204--betlec.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site configuration.

@victorDigital victorDigital added the dependencies Pull requests that update a dependency file label Nov 9, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants