Commit 9b29bcf
fix(deps): dompurify 3.4.12 -> 3.4.13 (GHSA IN_PLACE hook removal XSS) (#303)
A new advisory landed between this release's up-front Dependabot check (0 alerts)
and its post-merge re-check (1). Medium severity, runtime scope: removing an
IN_PLACE hook can leave a detached subtree executable.
This one matters here rather than being routine housekeeping. Agreement HTML is
rendered through SanitizedHtml/DOMPurify and that path is security-critical --
the sanitizer is the control, so a hole in the sanitizer is the whole control.
Lockfile updated in place with `npm update`; the multi-platform entries are
intact (346 linux entries), because re-resolving on Windows drops the linux
binaries and breaks the ubuntu runner.
Claude-Session: https://claude.ai/code/session_0185QebqzFLviQKtnEjLkC3H
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>1 parent bcc5522 commit 9b29bcf
1 file changed
Lines changed: 3 additions & 3 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
0 commit comments