Skip to content

fix(deps): update dependency dompurify to ^3.4.8 (stable1.0) - autoclosed#2593

Closed
renovate[bot] wants to merge 1 commit into
stable1.0from
renovate/stable1.0-dompurify-3.x
Closed

fix(deps): update dependency dompurify to ^3.4.8 (stable1.0) - autoclosed#2593
renovate[bot] wants to merge 1 commit into
stable1.0from
renovate/stable1.0-dompurify-3.x

Conversation

@renovate

@renovate renovate Bot commented May 10, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
dompurify ^3.4.0^3.4.8 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

cure53/DOMPurify (dompurify)

v3.4.8: DOMPurify 3.4.8

Compare Source

  • Cleaned up the repository root, renamed some and removed unneeded files
  • Fixed an issue with handling of Trusted Types policies, thanks @​fulstadev
  • Fixed the node iterator for better template scrubbing, thanks @​IamLeandrooooo
  • Included formerly missing LICENSE-MPL in published npm package, thanks @​asamuzaK
  • Bumped several dependencies where possible

v3.4.7: DOMPurify 3.4.7

Compare Source

  • Hardened the handling of Shadow Roots when using IN_PLACE, thanks @​GameZoneHacker
  • Removed a problem leading to permanent hook pollution, thanks @​offset
  • Refactored the test suite and expanded test coverage significantly

v3.4.6: DOMPurify 3.4.6

Compare Source

  • Fixed several issues with DOM Clobbering in IN_PLACE mode, thanks @​offset & @​Bankde
  • Hardened the checks for cross-realm IN_PLACE and Shadow DOM sanitization, thanks @​offset & @​Bankde
  • Added more test coverage for IN_PLACE and general DOM Clobbering attacks
  • Bumped several dependencies where possible

v3.4.5

Compare Source

v3.4.4: DOMPurify 3.4.4

Compare Source

  • Added the selectedcontent element to default allow-list, thanks @​lukewarlow
  • Added the command and commandfor attributes to default allowed-list, thanks @​lukewarlow
  • Added better template scrubbing for IN_PLACE operations, thanks @​DEMON1A
  • Added stronger checks for cross-realm windows, thanks @​DEMON1A & @​fg0x0
  • Updated demo website and made sure it uses the latest from main
  • Updated existing workflows, fuzzer, dependabot, etc., added more tests
  • Bumped several dependencies where possible

v3.4.3

Compare Source

v3.4.2: DOMPurify 3.4.2

Compare Source

  • Fixed an issue with URI validation on attributes allowed via ADD_ATTR callback, thanks @​nelstrom
  • Fixed an issue with source maps referring to non-existing files, thanks @​cmdcolin
  • Updated existing workflows, fuzzer, release signing, etc., added more tests
  • Bumped several dependencies where possible

Configuration

📅 Schedule: (in timezone Europe/Berlin)

  • Branch creation
    • "every weekend"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added 3. to review Waiting for reviews dependencies Pull requests that update a dependency file labels May 10, 2026
@renovate renovate Bot requested a review from enjeck May 10, 2026 16:23
@renovate renovate Bot added the dependencies Pull requests that update a dependency file label May 10, 2026
@renovate renovate Bot requested a review from blizzz as a code owner May 10, 2026 16:23
@renovate renovate Bot added the 3. to review Waiting for reviews label May 10, 2026
@renovate renovate Bot force-pushed the renovate/stable1.0-dompurify-3.x branch 2 times, most recently from 3161ea6 to 935b57d Compare May 20, 2026 12:30
@renovate renovate Bot changed the title fix(deps): update dependency dompurify to ^3.4.2 (stable1.0) fix(deps): update dependency dompurify to ^3.4.3 (stable1.0) May 20, 2026
@renovate renovate Bot force-pushed the renovate/stable1.0-dompurify-3.x branch from 935b57d to f6bad16 Compare May 25, 2026 08:26
@renovate renovate Bot changed the title fix(deps): update dependency dompurify to ^3.4.3 (stable1.0) fix(deps): update dependency dompurify to ^3.4.5 (stable1.0) May 25, 2026
@renovate renovate Bot force-pushed the renovate/stable1.0-dompurify-3.x branch from f6bad16 to 3ab8d18 Compare June 2, 2026 14:01
@renovate renovate Bot changed the title fix(deps): update dependency dompurify to ^3.4.5 (stable1.0) fix(deps): update dependency dompurify to ^3.4.6 (stable1.0) Jun 2, 2026
@renovate renovate Bot force-pushed the renovate/stable1.0-dompurify-3.x branch from 3ab8d18 to 4b7a4f5 Compare June 3, 2026 13:36
@renovate renovate Bot changed the title fix(deps): update dependency dompurify to ^3.4.6 (stable1.0) fix(deps): update dependency dompurify to ^3.4.7 (stable1.0) Jun 3, 2026
@renovate renovate Bot force-pushed the renovate/stable1.0-dompurify-3.x branch from 4b7a4f5 to bf6297a Compare June 10, 2026 13:43
@renovate renovate Bot changed the title fix(deps): update dependency dompurify to ^3.4.7 (stable1.0) fix(deps): update dependency dompurify to ^3.4.8 (stable1.0) Jun 10, 2026
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@enjeck enjeck force-pushed the renovate/stable1.0-dompurify-3.x branch from bf6297a to b1af527 Compare June 16, 2026 05:21
@renovate renovate Bot changed the title fix(deps): update dependency dompurify to ^3.4.8 (stable1.0) fix(deps): update dependency dompurify to ^3.4.8 (stable1.0) - autoclosed Jun 16, 2026
@renovate renovate Bot closed this Jun 16, 2026
@renovate renovate Bot deleted the renovate/stable1.0-dompurify-3.x branch June 16, 2026 05:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review Waiting for reviews dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants