Skip to content

chore(deps): bump dompurify from 3.4.13 to 3.4.14 - #283

Closed
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/dompurify-3.4.14
Closed

chore(deps): bump dompurify from 3.4.13 to 3.4.14#283
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/dompurify-3.4.14

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 30, 2026

Copy link
Copy Markdown
Contributor

Bumps dompurify from 3.4.13 to 3.4.14.

Release notes

Sourced from dompurify's releases.

DOMPurify 3.4.14

  • Fixed an issue with possible bypasses when risky tags are allow-listed, thanks @​AlirezaRouhbakhsh
  • Fixed a couple of edge cases with mixed document contexts, thanks @​fishjojo1
  • Added the SVG pointer-events and vector-effect presentation attributes to the allow-list, thanks @​Jaybhade
  • Conducted another refactoring run, removed dead branches and duplicated logic, flattened attribute validation
  • Updated the documentation in several spots, README, wiki, etc., thanks @​Akokonunes
  • Updated several development dependencies and CI workflow actions
Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 30, 2026
@github-actions

Copy link
Copy Markdown

⚠️ CodeCoraDev CLA Bot

Hi @dependabot[bot]! Thanks for your contribution.

Before this PR can be reviewed, please sign our Contributor License Agreement:


By signing, you agree to the terms in CLA_INDIVIDUAL.md or CLA_CORPORATE.md.

Bumps [dompurify](https://github.com/cure53/DOMPurify) from 3.4.13 to 3.4.14.
- [Release notes](https://github.com/cure53/DOMPurify/releases)
- [Commits](cure53/DOMPurify@3.4.13...3.4.14)

---
updated-dependencies:
- dependency-name: dompurify
  dependency-version: 3.4.14
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/dompurify-3.4.14 branch from 244a68d to d3c6ed7 Compare September 5, 2026 11:08
@ajianaz

ajianaz commented Sep 6, 2026

Copy link
Copy Markdown
Collaborator

Absorbed into the consolidated batch #319 (dependabot branches fail the repo's CLA/branch-naming gates). Thanks!

@ajianaz ajianaz closed this Sep 6, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 6, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/dompurify-3.4.14 branch September 6, 2026 13:11
ajianaz added a commit that referenced this pull request Sep 6, 2026
…vity tests (#319)

* chore(deps): batch bump JS + Rust dependencies (absorb dependabot #283-287, #313-317)

Absorb dependabot #283-287, #313-317 in one auditable batch.

Also pins activity tests to a fixed Wednesday clock - the Sunday-flaky
2 failures (noted in #309) are gone for good.

* chore(deps): sync package-lock.json with bumped JS deps

CI runs npm ci, which requires package-lock.json in sync with
package.json - bun.lock alone does not satisfy it.

---------

Co-authored-by: ajianaz <ajianaz@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant