Skip to content

[stable34] chore(deps): Bump dompurify from 3.4.2 to 3.4.5 in /build/frontend-legacy#60690

Merged
AndyScherzinger merged 2 commits into
stable34from
dependabot/npm_and_yarn/build/frontend-legacy/stable34/dompurify-3.4.5
May 25, 2026
Merged

[stable34] chore(deps): Bump dompurify from 3.4.2 to 3.4.5 in /build/frontend-legacy#60690
AndyScherzinger merged 2 commits into
stable34from
dependabot/npm_and_yarn/build/frontend-legacy/stable34/dompurify-3.4.5

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 23, 2026

Bumps dompurify from 3.4.2 to 3.4.5.

Release notes

Sourced from dompurify's releases.

DOMPurify 3.4.5

  • Fixed a bypass caused by the new HTML element selectedcontent added in 3.4.4, thanks @​KabirAcharya

Note that this is a security release for an issue introduced in 3.4.4 and should be upgraded to immediately.

DOMPurify 3.4.4

  • Added the selectedcontent element to default allow-list, thanks @​lukewarlow
  • Added the command and commandfor attributes to default allowed-list, thanks @​lukewarlow
  • Added better template scrubbing for IN_PLACE operations, thanks @​DEMON1A
  • Added stronger checks for cross-realm windows, thanks @​DEMON1A & @​fg0x0
  • Updated demo website and made sure it uses the latest from main
  • Updated existing workflows, fuzzer, dependabot, etc., added more tests
  • Bumped several dependencies where possible

🚨 This release had been flagged as deprecated, please use DOMPurify 3.4.5 instead 🚨

DOMPurify 3.4.3

  • Fixed an issue with handling of nested Shadow DOM trees, thanks @​fishjojo1
  • Fixed the template regexes to be more robust against ReDoS attacks, thanks @​aleung27
  • Updated the node iteration code to catch more Shadow DOM related issues
  • Updated Playwright and added Node 26 to test matrix
  • Updated existing workflows, fuzzer, release signing, etc., added more tests
  • Bumped several dependencies where possible
Commits

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot Bot requested a review from a team as a code owner May 23, 2026 02:07
@dependabot dependabot Bot requested a review from a team as a code owner May 23, 2026 02:07
@dependabot dependabot Bot requested review from nfebe, sorbaugh and susnux and removed request for a team May 23, 2026 02:07
@AndyScherzinger AndyScherzinger added this to the Nextcloud 34 milestone May 24, 2026
@AndyScherzinger AndyScherzinger force-pushed the dependabot/npm_and_yarn/build/frontend-legacy/stable34/dompurify-3.4.5 branch from aa4e382 to 3f41840 Compare May 24, 2026 19:45
@AndyScherzinger
Copy link
Copy Markdown
Member

/compile

dependabot Bot and others added 2 commits May 25, 2026 22:33
Bumps [dompurify](https://github.com/cure53/DOMPurify) from 3.4.2 to 3.4.5.
- [Release notes](https://github.com/cure53/DOMPurify/releases)
- [Commits](cure53/DOMPurify@3.4.2...3.4.5)

---
updated-dependencies:
- dependency-name: dompurify
  dependency-version: 3.4.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: nextcloud-command <nextcloud-command@users.noreply.github.com>
@AndyScherzinger AndyScherzinger force-pushed the dependabot/npm_and_yarn/build/frontend-legacy/stable34/dompurify-3.4.5 branch from 27bd185 to 035274a Compare May 25, 2026 20:34
@AndyScherzinger AndyScherzinger disabled auto-merge May 25, 2026 21:21
@AndyScherzinger AndyScherzinger merged commit 719b469 into stable34 May 25, 2026
123 of 131 checks passed
@AndyScherzinger AndyScherzinger deleted the dependabot/npm_and_yarn/build/frontend-legacy/stable34/dompurify-3.4.5 branch May 25, 2026 21:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants