Skip to content

build(deps): bump sanitize-html from 2.17.6 to 2.17.7 - #112

Merged
wu21-web merged 1 commit into
mainfrom
dependabot/npm_and_yarn/sanitize-html-2.17.7
Aug 18, 2026
Merged

build(deps): bump sanitize-html from 2.17.6 to 2.17.7#112
wu21-web merged 1 commit into
mainfrom
dependabot/npm_and_yarn/sanitize-html-2.17.7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 17, 2026

Copy link
Copy Markdown
Contributor

Bumps sanitize-html from 2.17.6 to 2.17.7.

Changelog

Sourced from sanitize-html's changelog.

2.17.7 (2026-08-13)

Security

  • Fixed an XSS / URL scheme policy bypass affecting configurations that allow the SVG animation elements (animate, animateColor, animateMotion, animateTransform or set) together with attributeName and one of the animation value attributes. The default configuration was not affected, as these elements are not in the default allowedTags. apostrophecms was not affected. Thanks to koyokr for responsibly disclosing the vulnerability (GHSA-g8qq-57p8-ggw5).
Commits

@dependabot dependabot Bot added dependencies javascript Pull requests that update javascript code labels Aug 17, 2026
@dependabot
dependabot Bot requested a review from wu21-web as a code owner August 17, 2026 20:56
@dependabot dependabot Bot added dependencies javascript Pull requests that update javascript code labels Aug 17, 2026
@vercel

vercel Bot commented Aug 17, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
me-reader Ready Ready Preview Aug 18, 2026 2:47am

@wu21-web

Copy link
Copy Markdown
Owner

@dependabot rebase

@dependabot @github

dependabot Bot commented on behalf of github Aug 18, 2026

Copy link
Copy Markdown
Contributor Author

Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry!

If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

@wu21-web

Copy link
Copy Markdown
Owner

@dependabot recreate

Bumps [sanitize-html](https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html) from 2.17.6 to 2.17.7.
- [Changelog](https://github.com/apostrophecms/apostrophe/blob/main/packages/sanitize-html/CHANGELOG.md)
- [Commits](https://github.com/apostrophecms/apostrophe/commits/HEAD/packages/sanitize-html)

---
updated-dependencies:
- dependency-name: sanitize-html
  dependency-version: 2.17.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/sanitize-html-2.17.7 branch from 45ea1c0 to 5e366c5 Compare August 18, 2026 02:47
@wu21-web
wu21-web merged commit 252c32b into main Aug 18, 2026
6 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/sanitize-html-2.17.7 branch August 18, 2026 02:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant