Skip to content

chore(deps): update all non-major dependencies#1102

Open
github-actions[bot] wants to merge 1 commit into
mainfrom
buddy-bot/update-non-major-updates
Open

chore(deps): update all non-major dependencies#1102
github-actions[bot] wants to merge 1 commit into
mainfrom
buddy-bot/update-non-major-updates

Conversation

@github-actions
Copy link
Copy Markdown
Contributor

@github-actions github-actions Bot commented Apr 14, 2026

This PR contains the following updates:

npm

Package Change Age Adoption Passing Confidence
dompurify (source) 3.4.2 -> 3.4.5 age adoption passing confidence

Release Notes

cure53/DOMPurify (dompurify)

3.4.2 -> 3.4.5

3.4.5

Compare Source

  • Fixed a bypass caused by the new HTML element selectedcontent added in 3.4.4, thanks KabirAcharya

Note that this is a security release for an issue introduced in 3.4.4 and should be upgraded to immediately.

Released by cure53 on 5/18/2026

3.4.4

Compare Source

  • Added the selectedcontent element to default allow-list, thanks lukewarlow
  • Added the command and commandfor attributes to default allowed-list, thanks lukewarlow
  • Added better template scrubbing for IN_PLACE operations, thanks DEMON1A
  • Added stronger checks for cross-realm windows, thanks DEMON1A & fg0x0
  • Updated demo website and made sure it uses the latest from main
  • Updated existing workflows, fuzzer, dependabot, etc., added more tests
  • Bumped several dependencies where possible

🚨 This release had been flagged as deprecated, please use DOMPurify 3.4.5 instead 🚨

Released by cure53 on 5/17/2026

3.4.3

Compare Source

  • Fixed an issue with handling of nested Shadow DOM trees, thanks fishjojo1
  • Fixed the template regexes to be more robust against ReDoS attacks, thanks aleung27
  • Updated the node iteration code to catch more Shadow DOM related issues
  • Updated Playwright and added Node 26 to test matrix
  • Updated existing workflows, fuzzer, release signing, etc., added more tests
  • Bumped several dependencies where possible

Released by cure53 on 5/13/2026


📊 Package Statistics

  • dompurify: 33,988,855 weekly downloads

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Buddy 🤖

@netlify
Copy link
Copy Markdown

netlify Bot commented Apr 14, 2026

Deploy Preview for ts-validation failed. Why did it fail? →

Name Link
🔨 Latest commit 1a178bb
🔍 Latest deploy log https://app.netlify.com/projects/ts-validation/deploys/6a0c5f78aab45c00088c80f8

@github-actions github-actions Bot force-pushed the buddy-bot/update-non-major-updates branch 21 times, most recently from d4ae7bc to 7f73325 Compare April 16, 2026 03:03
@github-actions github-actions Bot force-pushed the buddy-bot/update-non-major-updates branch 29 times, most recently from 73077fc to 54f1332 Compare April 19, 2026 12:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants