From aedf7e535c9e609d6622d26042714bdb4304d9a9 Mon Sep 17 00:00:00 2001 From: DeepSource Bot Date: Fri, 25 Apr 2025 18:33:57 +0000 Subject: [PATCH] =?UTF-8?q?fix(deps):=20update=20npm/dompurify=20from=203.?= =?UTF-8?q?0.6=20=E2=86=92=203.1.3=20fix(deps):=20update=20npm/dompurify?= =?UTF-8?q?=20from=203.0.6=20=E2=86=92=203.1.3?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit This pull request addresses security vulnerabilities in this repository by updating dependencies to a safe version. We recommend manually auditing the package manifest files to verify the fixes. ### Upgrade Summary **dompurify**: 3.0.6 → 3.1.3 - Fixes [CVE-2024-47875](https://nvd.nist.gov/vuln/detail/CVE-2024-47875) (High severity) - References: - [https://github.com/cure53/DOMPurify/security/advisories/GHSA-gx9m-whjm-85jf](https://github.com/cure53/DOMPurify/security/advisories/GHSA-gx9m-whjm-85jf) - [https://nvd.nist.gov/vuln/detail/CVE-2024-47875](https://nvd.nist.gov/vuln/detail/CVE-2024-47875) - [https://github.com/cure53/DOMPurify/commit/0ef5e537a514f904b6aa1d7ad9e749e365d7185f](https://github.com/cure53/DOMPurify/commit/0ef5e537a514f904b6aa1d7ad9e749e365d7185f) - [https://github.com/cure53/DOMPurify/commit/6ea80cd8b47640c20f2f230c7920b1f4ce4fdf7a](https://github.com/cure53/DOMPurify/commit/6ea80cd8b47640c20f2f230c7920b1f4ce4fdf7a) - [https://github.com/cure53/DOMPurify](https://github.com/cure53/DOMPurify) - [https://github.com/cure53/DOMPurify/blob/0ef5e537a514f904b6aa1d7ad9e749e365d7185f/test/test-suite.js#L2098](https://github.com/cure53/DOMPurify/blob/0ef5e537a514f904b6aa1d7ad9e749e365d7185f/test/test-suite.js#L2098) --- 🤖 This pull request was automatically generated by DeepSource SCA. To view all vulnerabilities in this repository, please visit the [dashboard](https://app.deepsource.com/gh/QuackatronHQ/posthog/dependencies/). --- pnpm-lock.yaml | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index ec77db9f8312..a7fbf2cca6ea 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -208,7 +208,7 @@ importers: version: 1.11.11(patch_hash=lbfir4woetqmvzqg7l4q5mjtfq) dompurify: specifier: ^3.0.6 - version: 3.0.6 + version: 3.1.3 esbuild: specifier: ^0.19.8 version: 0.19.8 @@ -8516,8 +8516,8 @@ packages: resolution: {integrity: sha512-cgwlv/1iFQiFnU96XXgROh8xTeetsnJiDsTc7TYCLFd9+/WNkIqPTxiM/8pSd8VIrhXGTf1Ny1q1hquVqDJB5w==} engines: {node: '>= 4'} - dompurify@3.0.6: - resolution: {integrity: sha512-ilkD8YEnnGh1zJ240uJsW7AzE+2qpbOUYjacomn3AvJ6J4JhKGSZ2nh4wUIXPZrEPppaCLx5jFe8T89Rk8tQ7w==} + dompurify@3.1.3: + resolution: {integrity: sha512-5sOWYSNPaxz6o2MUPvtyxTTqR4D3L77pr5rUQoWgD5ROQtVIZQgJkXbo1DLlK3vj11YGw5+LnF4SYti4gZmwng==} domutils@1.7.0: resolution: {integrity: sha512-Lgd2XcJ/NjEw+7tFvfKxOzCYKZsdct5lczQ2ZaQY8Djz7pfAD3Gbp8ySJWtreII/vDlMVmxwa6pHmdxIYgttDg==} @@ -26432,7 +26432,7 @@ snapshots: dependencies: domelementtype: 2.3.0 - dompurify@3.0.6: {} + dompurify@3.1.3: {} domutils@1.7.0: dependencies: