Skip to content

Commit 9b29bcf

Browse files
fix(deps): dompurify 3.4.12 -> 3.4.13 (GHSA IN_PLACE hook removal XSS) (#303)
A new advisory landed between this release's up-front Dependabot check (0 alerts) and its post-merge re-check (1). Medium severity, runtime scope: removing an IN_PLACE hook can leave a detached subtree executable. This one matters here rather than being routine housekeeping. Agreement HTML is rendered through SanitizedHtml/DOMPurify and that path is security-critical -- the sanitizer is the control, so a hole in the sanitizer is the whole control. Lockfile updated in place with `npm update`; the multi-platform entries are intact (346 linux entries), because re-resolving on Windows drops the linux binaries and breaks the ubuntu runner. Claude-Session: https://claude.ai/code/session_0185QebqzFLviQKtnEjLkC3H Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
1 parent bcc5522 commit 9b29bcf

1 file changed

Lines changed: 3 additions & 3 deletions

File tree

package-lock.json

Lines changed: 3 additions & 3 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)