Closed dependabot[bot] closed 8 months ago
@dependabot squash and merge
On Fri, Mar 1, 2024 at 7:33 AM dependabot[bot] @.***> wrote:
This automated pull request fixes a security vulnerability https://github.com/jjj333-p/dendrite-admin-interface/security/dependabot/3 (moderate severity).
Learn more about Dependabot security updates https://docs.github.com/github/managing-security-vulnerabilities/configuring-dependabot-security-updates.
Bumps sanitize-html https://github.com/apostrophecms/sanitize-html from 2.11.0 to 2.12.1. Changelog
Sourced from sanitize-html's changelog https://github.com/apostrophecms/sanitize-html/blob/main/CHANGELOG.md.
2.12.1 (2024-02-22)
- Do not parse sourcemaps in post-css. This fixes a vulnerability in which information about the existence or non-existence of files on a server could be disclosed via properly crafted HTML input when the style attribute is allowed by the configuration. Thanks to the Snyk Security team https://snyk.io/ for the disclosure and to Dylan Armstrong https://dylan.is/ for the fix.
2.12.0 (2024-02-21)
-
Introduced the allowedEmptyAttributes option, enabling explicit specification of empty string values for select attributes, with the default attribute set to alt. Thanks to Na https://github.com/zhna123 for the contribution.
Clarified the use of SVGs with a new test and changes to documentation. Thanks to Gauav Kumar https://github.com/gkumar9891 for the contribution.
Do not process source maps when processing style tags with PostCSS.
Commits
- 4a7d7dd https://github.com/apostrophecms/sanitize-html/commit/4a7d7dd099b41c909f2faac056d34cf027515079 Merge pull request #654 https://redirect.github.com/apostrophecms/sanitize-html/issues/654 from apostrophecms/release-2.12.1
- f8e02be https://github.com/apostrophecms/sanitize-html/commit/f8e02be9fc3ea639edccfcaa50c6e71a22b2c068 release 2.12.1
- c5dbdf7 https://github.com/apostrophecms/sanitize-html/commit/c5dbdf77fe8b836d3bf4554ea39edb45281ec0b4 Merge pull request #650 https://redirect.github.com/apostrophecms/sanitize-html/issues/650 from dylanarmstrong/fix/ignore-source-maps
- 5a5a74e https://github.com/apostrophecms/sanitize-html/commit/5a5a74e179ef98075a0c61789f64e009f6b4ac29 Merge pull request #652 https://redirect.github.com/apostrophecms/sanitize-html/issues/652 from apostrophecms/add-thanks-to-changelog
- ee71ff0 https://github.com/apostrophecms/sanitize-html/commit/ee71ff0c04b2e00f730b8e29206cd65209cca5c4 Add community contribution thanks you
- a226fe7 https://github.com/apostrophecms/sanitize-html/commit/a226fe7af4c3a8faee6d114984da3f2964e4ae65 Merge pull request #651 https://redirect.github.com/apostrophecms/sanitize-html/issues/651 from apostrophecms/release-2.12.0
- ff18600 https://github.com/apostrophecms/sanitize-html/commit/ff18600f01a390c81c27442d6e858ec0eb4ef67e release 2.12.0
- 1e2294c https://github.com/apostrophecms/sanitize-html/commit/1e2294c8001ce07c89448e03289818da631795ba test: added test for postcss map
- c376501 https://github.com/apostrophecms/sanitize-html/commit/c376501b9a066479736f0a088fba3492e7122811 doc: update changelog
- 075499d https://github.com/apostrophecms/sanitize-html/commit/075499d1b98c387f4200fd59972ca9b15796b51b fix: ignore source maps when processing with postcss
- Additional commits viewable in compare view https://github.com/apostrophecms/sanitize-html/compare/2.11.0...2.12.1
[image: Dependabot compatibility score] https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- @dependabot rebase will rebase this PR
- @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
- @dependabot merge will merge this PR after your CI passes on it
- @dependabot squash and merge will squash and merge this PR after your CI passes on it
- @dependabot cancel merge will cancel a previously requested merge and block automerging
- @dependabot reopen will reopen this PR if it is closed
- @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- @dependabot show
ignore conditions will show all of the ignore conditions of the specified dependency - @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page https://github.com/jjj333-p/dendrite-admin-interface/network/alerts.
You can view, comment on, or merge this pull request online at:
https://github.com/jjj333-p/dendrite-admin-interface/pull/18 Commit Summary
- a810ee4 https://github.com/jjj333-p/dendrite-admin-interface/pull/18/commits/a810ee47668ee070827b6e02a3231ab7048c0216 Bump sanitize-html from 2.11.0 to 2.12.1
File Changes
(1 file https://github.com/jjj333-p/dendrite-admin-interface/pull/18/files)
- M package-lock.json https://github.com/jjj333-p/dendrite-admin-interface/pull/18/files#diff-053150b640a7ce75eff69d1a22cae7f0f94ad64ce9a855db544dda0929316519 (6)
Patch Links:
- https://github.com/jjj333-p/dendrite-admin-interface/pull/18.patch
- https://github.com/jjj333-p/dendrite-admin-interface/pull/18.diff
— Reply to this email directly, view it on GitHub https://github.com/jjj333-p/dendrite-admin-interface/pull/18, or unsubscribe https://github.com/notifications/unsubscribe-auth/AWNJYMD4WK2ENTAUAXFGAX3YWC3VZAVCNFSM6AAAAABECEJGLWVHI2DSMVQWIX3LMV43ASLTON2WKOZSGE3DGOBXGEZDQNY . You are receiving this because you are subscribed to this thread.Message ID: @.***>
Bumps sanitize-html from 2.11.0 to 2.12.1.
Changelog
Sourced from sanitize-html's changelog.
Commits
4a7d7dd
Merge pull request #654 from apostrophecms/release-2.12.1f8e02be
release 2.12.1c5dbdf7
Merge pull request #650 from dylanarmstrong/fix/ignore-source-maps5a5a74e
Merge pull request #652 from apostrophecms/add-thanks-to-changelogee71ff0
Add community contribution thanks youa226fe7
Merge pull request #651 from apostrophecms/release-2.12.0ff18600
release 2.12.01e2294c
test: added test for postcss mapc376501
doc: update changelog075499d
fix: ignore source maps when processing with postcssDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show