chore(deps): bump sanitize-html from 2.13.0 to 2.17.7 - #4549
dependabot[bot] wants to merge 1 commit into
Conversation
PR SummaryMedium Risk Overview The integrations library uses this library when sanitizing HTML from external sources (Dev.to, Discourse, Slack, Reddit, etc.). The newer release pulls in htmlparser2 12 and related DOM parsing deps, and addresses several XSS / allowlist bypass issues in earlier 2.17.x releases. Runtime note: Reviewed by Cursor Bugbot for commit 395c4ed. Bugbot is set up for automated code reviews on this repo. Configure here. |
|
|
|
Your PR title doesn't contain a Jira issue key. Consider adding it for better traceability. Example:
Projects:
Please add a Jira issue key to your PR title. |
e2f4aed to
faecfba
Compare
f47d561 to
5fc3c4e
Compare
Bumps [sanitize-html](https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html) from 2.13.0 to 2.17.7. - [Changelog](https://github.com/apostrophecms/apostrophe/blob/main/packages/sanitize-html/CHANGELOG.md) - [Commits](https://github.com/apostrophecms/apostrophe/commits/sanitize-html@2.17.7/packages/sanitize-html) --- updated-dependencies: - dependency-name: sanitize-html dependency-version: 2.17.7 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
5fc3c4e to
395c4ed
Compare
Bumps sanitize-html from 2.13.0 to 2.17.7.
Changelog
Sourced from sanitize-html's changelog.
... (truncated)
Commits
72f4531Latest reconciliation q2 m3 2026 (#5555)207846aready for 4.32.0 release (#5513)f820033Latest reconciliation q2 m2 (#5511)2427508release and changelog edits (#5465)5a88e96Latest security q2 (#5464)958d162merge main to latest (#5460)e9b0ab0release only (changelogs formatted) (#5408)f03fa5bLatest security merge (#5407)96cf174For release only (#5381)7ca2d16Merge commit from fork