hexojs / hexo-renderer-marked

Markdown renderer for Hexo
MIT License
179 stars 94 forks source link

chore(deps): bump dompurify from 2.4.4 to 3.0.0 #243

Closed dependabot[bot] closed 1 year ago

dependabot[bot] commented 1 year ago

Bumps dompurify from 2.4.4 to 3.0.0.

Release notes

Sourced from dompurify's releases.

DOMPurify 3.0.0

  • Removed all code that is for MSIE-only
  • Removed all tests that are for MSIE-only
  • Modified documentation to reflect new state of MSIE support
  • Added support for ALLOW_SELF_CLOSE_IN_ATTR flag, thanks @​edg2s @​AndreVirtimo
  • Added better support for shadowrootmode, thanks @​mfreed7

NOTE Please use the 2.4.4 release if you still need MSIE support, 3.0.0 comes without the MSIE overhead

Commits
  • 5dcf2a0 chore: preparing 3.0.0 release
  • 6e98d48 see #767
  • 8dd2763 test: Added 3.x tag only for 3.x branch actions
  • 4394af9 Merge branch 'main' into 3.x
  • ed9e938 chore: Added checks to set isSupported to false for MSIE
  • 600fa00 test: Fixed two more breaking commas, duh
  • 639c63a test: Fixed a breaking comma
  • 5deaa35 Merge pull request #762 from cure53/3.x
  • 5945d66 docs: Upodated README to be more accurate for MSIE
  • 0ace391 Merge pull request #759 from cure53/main
  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
coveralls commented 1 year ago

Coverage Status

Coverage: 100.0%. Remained the same when pulling 31232803b9730519c3fedff657e7e662e9642721 on dependabot/npm_and_yarn/dompurify-3.0.0 into d10fd5f50694df6f27e83d2fe760bc38675a6528 on master.

dependabot[bot] commented 1 year ago

Superseded by #244.