🚨 [security] Update loofah: 2.2.2 → 2.3.1 (minor) #213
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
🚨 Your current dependencies have known security vulnerabilities 🚨
This dependency update fixes known security vulnerabilities. Please see the details below and assess their impact carefully. We recommend to merge and deploy this as soon as possible!
Here is everything you need to know about this update. Please take a good look at what changed and the test results before merging this pull request.
What changed?
Security Advisories 🚨
🚨 Loofah XSS Vulnerability
🚨 Loofah XSS Vulnerability
Release Notes
2.3.1
2.3.0 (from changelog)
2.2.3
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 48 commits:
version bump to v2.3.1
Merge pull request #172 from flavorjones/171-xss-vulnerability
update CHANGELOG
mitigate XSS vulnerability in SVG animate attributes
rufo formatting
formatting in README
update CHANGELOG with release date
update dev gemspec
version bump to v2.3.0
update dev deps
update README to work with modern Hoe
update Manifest
Merge branch 'jf.safelist'
formatting CHANGELOG
Only call deprecate_constant if available
Use safelist consistently
Use safelist(s), allowlist(s) where applicable
update CHANGELOG
ci: remove unused code from rake-test/run.sh
Merge pull request #167 from jobscore/allow-html-property-contenteditable
Merge pull request #168 from georgeclaghorn/border-width-keyword-values
Allow the thin and thick CSS keywords
Allow HTML property: contenteditable
update to latest concourse-gem
update dev dependencies
changelog: update for #162
Merge pull request #162 from jaredbeck/allow_list-style
changelog: update for #165
Merge pull request #165 from asok/correct-css-keywordish-regexp
Fix test for style attribute scrubbing
Add a test for testing style attribute scrubbing
Correct the regexp for kewordish css property which hold a hex value
Allow CSS property `list-style`
cherry-pick v2.2.3 changelog entry
remove the svg animate attribute `from` from the allowlist
remove versioneye from readme
Merge branch 'flavorjones-allowlist-changes'
update CHANGELOG
Allow greater precision in values of shorthand css elements
failing test for high-precision CSS values
update CHANGELOG
expand allowed protocols to allow `tel:` and `line:`
expand set of allowed CSS functions
reformat `whitelist.rb`
scripts to inspect and compare DOMPurify metadata
add formatting to CHANGELOG
updated mailing list to a new Google Group
extract msword html data into an asset file
Release Notes
1.0.6
1.0.5
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 8 commits:
Release 1.0.6
Limit number values to a sensible range
Update history
Add project metadata to the gemspec
Release 1.0.5
Remove test files and omit them
Remove 1.9.3 from the test matrix
Update Travis test matrix
Commits
See the full diff on Github. The new version differs by 10 commits:
version bump to v2.4.0
update CHANGELOG in preparation for v2.4.0
update dev dependencies
Merge pull request #86 from eagletmt/skip-progress-when-chunked
Merge pull request #87 from halfbyte/patch-1
Make version in changelog fit release version.
Skip progress report when Content-Length is unavailable
update test:examples to libiconv 1.15
concourse: test most-recent two rubies
convert to using windows-ruby-dev-tools-release
Security Advisories 🚨
🚨 xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
🚨 Nokogiri gem, via libxslt, is affected by multiple vulnerabilities
🚨 Nokogiri Command Injection Vulnerability
🚨 Nokogiri gem, via libxslt, is affected by improper access control vulnerability
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with
@depfu rebase
.All Depfu comment commands