lukebrogan-mend / vulnerable-rust

0 stars 0 forks source link

Update Rust crate ammonia to 2.1.4 - autoclosed #33

Closed mend-for-github-com[bot] closed 1 year ago

mend-for-github-com[bot] commented 2 years ago

This PR contains the following updates:

Package Type Update Change
ammonia dependencies minor 2.0.0 -> 2.1.4

Release Notes

rust-ammonia/ammonia ### [`v2.1.4`](https://togithub.com/rust-ammonia/ammonia/blob/HEAD/CHANGELOG.md#​214) [Compare Source](https://togithub.com/rust-ammonia/ammonia/compare/v2.1.3...v2.1.4) - fix: split class name attribute by all ASCII whitespace, not just SP 0x20 (backported from 3.1.3) ### [`v2.1.3`](https://togithub.com/rust-ammonia/ammonia/blob/HEAD/CHANGELOG.md#​213) [Compare Source](https://togithub.com/rust-ammonia/ammonia/compare/v2.1.2...v2.1.3) - fix: unexpected namespace switches can allow XSS via svg/mathml parsing (backported from 3.1.2) ### [`v2.1.2`](https://togithub.com/rust-ammonia/ammonia/blob/HEAD/CHANGELOG.md#​212) [Compare Source](https://togithub.com/rust-ammonia/ammonia/compare/v2.1.1...v2.1.2) - Fix a memory leak caused by certain node types. ### [`v2.1.1`](https://togithub.com/rust-ammonia/ammonia/blob/HEAD/CHANGELOG.md#​211) [Compare Source](https://togithub.com/rust-ammonia/ammonia/compare/v2.1.0...v2.1.1) - Update dependencies ### [`v2.1.0`](https://togithub.com/rust-ammonia/ammonia/blob/HEAD/CHANGELOG.md#​210) [Compare Source](https://togithub.com/rust-ammonia/ammonia/compare/v2.0.0...v2.1.0) - Bump minimum supported Rust version to 1.30. - Fix a potential DoS attack from pathologically nested input.

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.