Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[PROD](renovate) Update dependency ckeditor/ckeditor to v4.24.0 - autoclosed #550

Closed
wants to merge 1 commit into from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Dec 3, 2022

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
ckeditor/ckeditor (source) 4.20.1 -> 4.24.0 age adoption passing confidence

Release Notes

ckeditor/ckeditor4-releases (ckeditor/ckeditor)

v4.24.0

Compare Source

⚠️️️ Please note that this release is a part of CKEditor 4 Extended Support Model, only available to customers who decided to acquire the LTS (Long Term Support) version of the editor. All editor versions below 4.24.0-lts can no longer be considered as secure! ⚠️

Security Updates:

  • Fixed cross-site scripting (XSS) vulnerability caused by incorrect CDATA detection reported by Michal Frýba, ALEF NULA.

    Issue summary: The vulnerability allowed to inject malformed HTML content bypassing Advanced Content Filtering mechanism, which could result in executing JavaScript code. See GHA for more details.

  • Fixed cross-site scripting (XSS) vulnerability in AJAX sample reported by Rafael Pedrero, see INCIBE report.

    Issue summary: The vulnerability allowed to execute JavaScript code by abusing the AJAX sample. See GHA for more details.

  • Cross-site scripting (XSS) vulnerability in samples with enabled the preview feature reported by Marcin Wyczechowski & Michał Majchrowicz, AFINE Team.

    Issue summary: The vulnerability allowed to execute JavaScript code by abusing the misconfigured preview feature. See GHA for more details.

You can read more details in the relevant security advisories. Contact us if you have more questions.

An upgrade is highly recommended!

Fixed Issues:

  • Fixed: The CDATA parsing mechanism incorrectly detects the end of CDATA content. This fix unifies how style and script elements are parsed with the browser's behavior.

v4.23.0

Compare Source

This release introduces the LTS (”Long Term Support”) version of the editor, available under commercial terms ("Extended Support Model").

If you acquired the Extended Support Model for CKEditor 4 LTS, please read the CKEditor 4 LTS key activation guide.

v4.22.1

Compare Source

⚠️ This is the last open source release of CKEditor 4. As announced in 2018, CKEditor 4 has reached its End of Life in June 2023.

New Features:

Fixed Issues:

  • #​5437: Fixed: Incorrect indication of selected items in combo boxes. The selected item was unmarked upon each opening of the combo box.
  • #​5495: Fixed: Insufficient color ratio for links inside Notifications.

Other Changes:

  • #​5412: Prevent using document.domain in Firefox in the Preview plugin.

Note: CKEditor 4.22.1 has been released immediately after 4.22.0 to fix the README issues on npm and contains no changes vs 4.22.0.

v4.22.0

Compare Source

⚠️ This is the last open source release of CKEditor 4. As announced in 2018, CKEditor 4 has reached its End of Life in June 2023.

New Features:

Fixed Issues:

  • #​5437: Fixed: Incorrect indication of selected items in combo boxes. The selected item was unmarked upon each opening of the combo box.
  • #​5495: Fixed: Insufficient color ratio for links inside Notifications.

Other Changes:

  • #​5412: Prevent using document.domain in Firefox in the Preview plugin.

Note: CKEditor 4.22.1 has been released immediately after 4.22.0 to fix the README issues on npm and contains no changes vs 4.22.0.

v4.21.0

Compare Source

Security Updates:

A cross-site scripting vulnerability has been discovered affecting Iframe Dialog and Media Embed plugins.

This vulnerability might affect a small percentage of integrators that depend on dynamic editor initialization/destroy mechanism. See GitHub advisory for more details.

Potential breaking changes

In some rare cases, a security release may introduce a breaking change to your application. We have provided configuration options that will help you mitigate any potential issues with the upgrade:

  • Starting from version 4.21, the Iframe Dialog plugin applies the sandbox attribute by default, which restricts JavaScript code execution in the iframe element. To change this behavior, configure the config.iframe_attributes option.
  • Starting from version 4.21, the Media Embed plugin regenerates the entire content of the embed widget by default. To change this behavior, configure the config.embed_keepOriginalContent option.

If you choose to change either of the above options, make sure to properly configure Content Security Policy to avoid any potential security issues that may arise from embedding iframe elements on your web page.

You can read more details in the relevant security advisory and contact us if you have more questions.

An upgrade is highly recommended!

New Features:

Fixed Issues:

  • #​5431: Fixed: No notification is shown when pasting or dropping unsupported image types into the editor.

v4.20.2

Compare Source

Fixed Issues:

  • #​439: Fixed: Incorrect Tab and Shift+Tab navigation for radio buttons inside the dialog.
  • #​4829: Fixed: Undo reversed entire table content instead of a single cell. Thanks to that fix, multiple changes in a table can be undone one by one.
  • #​5396: Fixed: Event listeners for popstate and hashchange events on the window, added by the Maximize plugin, were not removed when destroying the editor instance.
  • #​5414: Fixed: File and image uploaders based on the Upload Widget plugin and Easy Image plugin didn't fire the change event upon finishing upload, resulting in passing incorrect data in form controls for integration frameworks, like Reactive forms in Angular.
  • #​698: Fixed: An error was thrown after applying formatting to the widget with inline editable and switching to the source mode. Thanks to Glen!

API changes:


Configuration

📅 Schedule: Branch creation - "every weekend" in timezone Europe/Warsaw, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot added the dependencies Pull requests that update a dependency file label Dec 3, 2022
Copy link

@github-actions github-actions bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Scan Summary

Tool Critical High Medium Low Status
Dependency Scan (nodejs) 0 0 3 0
Dependency Scan (php) 0 0 1 0
Security Audit for Infrastructure 0 0 0 0
Secrets Audit 0 12 0 0

Recommendation

Please review the findings from Code scanning alerts before approving this pull request. You can also configure the build rules or add suppressions to customize this bot 👍

@renovate renovate bot changed the title [PROD](renovate) Update dependency ckeditor/ckeditor to v4.20.1 [PROD](renovate) Update dependency ckeditor/ckeditor to v4.20.1 - autoclosed Jan 13, 2023
@renovate renovate bot closed this Jan 13, 2023
@renovate renovate bot deleted the renovate/ckeditor-ckeditor-4.x-lockfile branch January 13, 2023 08:46
@renovate renovate bot changed the title [PROD](renovate) Update dependency ckeditor/ckeditor to v4.20.1 - autoclosed [PROD](renovate) Update dependency ckeditor/ckeditor to v4.20.1 Jan 13, 2023
@renovate renovate bot reopened this Jan 13, 2023
@renovate renovate bot restored the renovate/ckeditor-ckeditor-4.x-lockfile branch January 13, 2023 12:18
Copy link

@github-actions github-actions bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Scan Summary

Tool Critical High Medium Low Status
Dependency Scan (php) 0 0 1 0
Dependency Scan (nodejs) 0 0 3 0
Secrets Audit 0 12 0 0

Recommendation

Please review the findings from Code scanning alerts before approving this pull request. You can also configure the build rules or add suppressions to customize this bot 👍

@renovate renovate bot force-pushed the renovate/ckeditor-ckeditor-4.x-lockfile branch from d5e7351 to 5dbc4af Compare March 16, 2023 19:47
@renovate renovate bot changed the title [PROD](renovate) Update dependency ckeditor/ckeditor to v4.20.1 [PROD](renovate) Update dependency ckeditor/ckeditor to v4.20.2 Mar 16, 2023
Copy link

@github-actions github-actions bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Scan Summary

Tool Critical High Medium Low Status
Dependency Scan (universal) 0 1 0 0
Secrets Audit 0 12 0 0

Recommendation

Please review the findings from Code scanning alerts before approving this pull request. You can also configure the build rules or add suppressions to customize this bot 👍

@renovate renovate bot changed the title [PROD](renovate) Update dependency ckeditor/ckeditor to v4.20.2 [PROD](renovate) Update dependency ckeditor/ckeditor to v4.21.0 Mar 25, 2023
@renovate renovate bot force-pushed the renovate/ckeditor-ckeditor-4.x-lockfile branch from 5dbc4af to a843909 Compare March 25, 2023 04:23
@renovate renovate bot force-pushed the renovate/ckeditor-ckeditor-4.x-lockfile branch from a843909 to 8de7828 Compare July 1, 2023 03:21
@renovate renovate bot changed the title [PROD](renovate) Update dependency ckeditor/ckeditor to v4.21.0 [PROD](renovate) Update dependency ckeditor/ckeditor to v4.22.1 Jul 1, 2023
Copy link

@github-actions github-actions bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Scan Summary

Tool Critical High Medium Low Status
Dependency Scan (universal) 0 1 2 0
Secrets Audit 0 12 0 0

Recommendation

Please review the findings from Code scanning alerts before approving this pull request. You can also configure the build rules or add suppressions to customize this bot 👍

@renovate renovate bot force-pushed the renovate/ckeditor-ckeditor-4.x-lockfile branch from 8de7828 to 5e3c17c Compare October 23, 2023 14:42
@renovate renovate bot changed the title [PROD](renovate) Update dependency ckeditor/ckeditor to v4.22.1 [PROD](renovate) Update dependency ckeditor/ckeditor to v4.23.0 Oct 23, 2023
@renovate renovate bot force-pushed the renovate/ckeditor-ckeditor-4.x-lockfile branch from 5e3c17c to d085429 Compare February 7, 2024 15:31
@renovate renovate bot changed the title [PROD](renovate) Update dependency ckeditor/ckeditor to v4.23.0 [PROD](renovate) Update dependency ckeditor/ckeditor to v4.24.0 Feb 7, 2024
@renovate renovate bot changed the title [PROD](renovate) Update dependency ckeditor/ckeditor to v4.24.0 [PROD](renovate) Update dependency ckeditor/ckeditor to v4.24.0 - autoclosed Feb 20, 2024
@renovate renovate bot closed this Feb 20, 2024
@renovate renovate bot deleted the renovate/ckeditor-ckeditor-4.x-lockfile branch February 20, 2024 17:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file security findings
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant