Skip to content

fix(deps): update dependency dompurify to ^3.4.7 (main)#2703

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/main-dompurify-3.x
Open

fix(deps): update dependency dompurify to ^3.4.7 (main)#2703
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/main-dompurify-3.x

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Jun 6, 2026

This PR contains the following updates:

Package Change Age Confidence
dompurify ^3.4.5^3.4.7 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

cure53/DOMPurify (dompurify)

v3.4.7: DOMPurify 3.4.7

Compare Source

  • Hardened the handling of Shadow Roots when using IN_PLACE, thanks @​GameZoneHacker
  • Removed a problem leading to permanent hook pollution, thanks @​offset
  • Refactored the test suite and expanded test coverage significantly

v3.4.6: DOMPurify 3.4.6

Compare Source

  • Fixed several issues with DOM Clobbering in IN_PLACE mode, thanks @​offset & @​Bankde
  • Hardened the checks for cross-realm IN_PLACE and Shadow DOM sanitization, thanks @​offset & @​Bankde
  • Added more test coverage for IN_PLACE and general DOM Clobbering attacks
  • Bumped several dependencies where possible

Configuration

📅 Schedule: (in timezone Europe/Berlin)

  • Branch creation
    • "every weekend"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the 3. to review Waiting for reviews label Jun 6, 2026
@renovate renovate Bot requested a review from enjeck as a code owner June 6, 2026 00:30
@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Jun 6, 2026
@renovate renovate Bot requested a review from blizzz as a code owner June 6, 2026 00:30
@renovate renovate Bot added dependencies Pull requests that update a dependency file 3. to review Waiting for reviews labels Jun 6, 2026
@enjeck enjeck force-pushed the renovate/main-dompurify-3.x branch from 0884012 to ee0c000 Compare June 6, 2026 19:52
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@renovate renovate Bot force-pushed the renovate/main-dompurify-3.x branch from ee0c000 to b66b36b Compare June 6, 2026 21:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review Waiting for reviews dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants