[PR #1517] [MERGED] fix(deps): update dependency dompurify to v3.2.7 #1545

Closed
opened 2025-11-01 21:22:30 -05:00 by GiteaMirror · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/go-vikunja/vikunja/pull/1517
Author: @renovate[bot]
Created: 9/17/2025
Status: Merged
Merged: 9/17/2025
Merged by: @kolaente

Base: mainHead: renovate/dompurify-3.x


📝 Commits (1)

  • a0da279 fix(deps): update dependency dompurify to v3.2.7

📊 Changes

2 files changed (+6 additions, -6 deletions)

View changed files

📝 frontend/package.json (+1 -1)
📝 frontend/pnpm-lock.yaml (+5 -5)

📄 Description

Coming soon: The Renovate bot (GitHub App) will be renamed to Mend. PRs from Renovate will soon appear from 'Mend'. Learn more here.

This PR contains the following updates:

Package Change Age Confidence
dompurify 3.2.6 -> 3.2.7 age confidence

Release Notes

cure53/DOMPurify (dompurify)

v3.2.7: DOMPurify 3.2.7

Compare Source

  • Added new attributes and elements to default allow-list, thanks @​elrion018
  • Added tagName parameter to custom element attributeNameCheck, thanks @​nelstrom
  • Added better check for animated href attributes, thanks @​llamakko
  • Updated and improved the bundled types, thanks @​ssi02014
  • Updated several tests to better align with new browser encoding behaviors
  • Improved the handling of potentially risky content inside CDATA elements, thanks @​securityMB & @​terjanq
  • Improved the regular expression for raw-text elements to cover textareas, thanks @​securityMB & @​terjanq

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.


🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/go-vikunja/vikunja/pull/1517 **Author:** [@renovate[bot]](https://github.com/apps/renovate) **Created:** 9/17/2025 **Status:** ✅ Merged **Merged:** 9/17/2025 **Merged by:** [@kolaente](https://github.com/kolaente) **Base:** `main` ← **Head:** `renovate/dompurify-3.x` --- ### 📝 Commits (1) - [`a0da279`](https://github.com/go-vikunja/vikunja/commit/a0da2790927da22039c1a15dfa995fe152769007) fix(deps): update dependency dompurify to v3.2.7 ### 📊 Changes **2 files changed** (+6 additions, -6 deletions) <details> <summary>View changed files</summary> 📝 `frontend/package.json` (+1 -1) 📝 `frontend/pnpm-lock.yaml` (+5 -5) </details> ### 📄 Description Coming soon: The Renovate bot (GitHub App) will be renamed to Mend. PRs from Renovate will soon appear from 'Mend'. Learn more [here](https://redirect.github.com/renovatebot/renovate/discussions/37842). This PR contains the following updates: | Package | Change | Age | Confidence | |---|---|---|---| | [dompurify](https://redirect.github.com/cure53/DOMPurify) | [`3.2.6` -> `3.2.7`](https://renovatebot.com/diffs/npm/dompurify/3.2.6/3.2.7) | [![age](https://developer.mend.io/api/mc/badges/age/npm/dompurify/3.2.7?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/dompurify/3.2.6/3.2.7?slim=true)](https://docs.renovatebot.com/merge-confidence/) | --- ### Release Notes <details> <summary>cure53/DOMPurify (dompurify)</summary> ### [`v3.2.7`](https://redirect.github.com/cure53/DOMPurify/releases/tag/3.2.7): DOMPurify 3.2.7 [Compare Source](https://redirect.github.com/cure53/DOMPurify/compare/3.2.6...3.2.7) - Added new attributes and elements to default allow-list, thanks [@&#8203;elrion018](https://redirect.github.com/elrion018) - Added `tagName` parameter to custom element `attributeNameCheck`, thanks [@&#8203;nelstrom](https://redirect.github.com/nelstrom) - Added better check for animated `href` attributes, thanks [@&#8203;llamakko](https://redirect.github.com/llamakko) - Updated and improved the bundled types, thanks [@&#8203;ssi02014](https://redirect.github.com/ssi02014) - Updated several tests to better align with new browser encoding behaviors - Improved the handling of potentially risky content inside CDATA elements, thanks [@&#8203;securityMB](https://redirect.github.com/securityMB) & [@&#8203;terjanq](https://redirect.github.com/terjanq) - Improved the regular expression for raw-text elements to cover textareas, thanks [@&#8203;securityMB](https://redirect.github.com/securityMB) & [@&#8203;terjanq](https://redirect.github.com/terjanq) </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/go-vikunja/vikunja). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MS45Ny4xMCIsInVwZGF0ZWRJblZlciI6IjQxLjk3LjEwIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
GiteaMirror added the pull-request label 2025-11-01 21:22:30 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/vikunja#1545