thetallgrassnet / pokesite

Your one-stop Pokémon fan community and database
https://thetallgrass.net
GNU Affero General Public License v3.0
1 stars 0 forks source link

🚨 [security] Update loofah: 2.1.1 → 2.2.1 (minor) #296

Open depfu[bot] opened 6 years ago

depfu[bot] commented 6 years ago

🚨 Your version of loofah has known security vulnerabilities 🚨

Advisory: CVE-2018-8048 Disclosed: March 16, 2018 URL: https://github.com/flavorjones/loofah/issues/144

Loofah XSS Vulnerability

Loofah allows non-whitelisted attributes to be present in sanitized
output when input with specially-crafted HTML fragments.


🚨 We recommend to merge and deploy this update as soon as possible! 🚨


We've updated a dependency and here is what you need to know:

name version specification old version new version
loofah indirect dependency 2.1.1 2.2.1

Additionally, the update changed a few other dependencies as well:

action name old version new version
updated nokogiri 1.8.1 1.8.2

You should probably take a good look at the info here and the test results before merging this pull request, of course.

What changed?

↗️ loofah (indirect, 2.1.1 → 2.2.1) · Repo · Changelog

Release Notes

From the Github release:

Notably, this release mitigates CVE-2018-8048.

Commits

See the full diff on Github. The new version differs by 44 commits:

✳️ nokogiri (1.8.1 → 1.8.2) · Repo · Changelog

Commits

See the full diff on Github. The new version differs by 29 commits:


Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with @depfu rebase.

Depfu Status