Skip to content

chore(deps): update dependency dompurify@<3.4.0 to >=3.4.8#591

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/dompurify-3.4.0-3.x
Open

chore(deps): update dependency dompurify@<3.4.0 to >=3.4.8#591
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/dompurify-3.4.0-3.x

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented May 18, 2026

This PR contains the following updates:

Package Change Age Confidence
dompurify@<3.4.0 >=3.4.2>=3.4.8 age confidence

Release Notes

cure53/DOMPurify (dompurify@<3.4.0)

v3.4.8: DOMPurify 3.4.8

Compare Source

  • Cleaned up the repository root, renamed some and removed unneeded files
  • Fixed an issue with handling of Trusted Types policies, thanks @​fulstadev
  • Fixed the node iterator for better template scrubbing, thanks @​IamLeandrooooo
  • Included formerly missing LICENSE-MPL in published npm package, thanks @​asamuzaK
  • Bumped several dependencies where possible

v3.4.7: DOMPurify 3.4.7

Compare Source

  • Hardened the handling of Shadow Roots when using IN_PLACE, thanks @​GameZoneHacker
  • Removed a problem leading to permanent hook pollution, thanks @​offset
  • Refactored the test suite and expanded test coverage significantly

v3.4.6: DOMPurify 3.4.6

Compare Source

  • Fixed several issues with DOM Clobbering in IN_PLACE mode, thanks @​offset & @​Bankde
  • Hardened the checks for cross-realm IN_PLACE and Shadow DOM sanitization, thanks @​offset & @​Bankde
  • Added more test coverage for IN_PLACE and general DOM Clobbering attacks
  • Bumped several dependencies where possible

v3.4.5

Compare Source

v3.4.4: DOMPurify 3.4.4

Compare Source

  • Added the selectedcontent element to default allow-list, thanks @​lukewarlow
  • Added the command and commandfor attributes to default allowed-list, thanks @​lukewarlow
  • Added better template scrubbing for IN_PLACE operations, thanks @​DEMON1A
  • Added stronger checks for cross-realm windows, thanks @​DEMON1A & @​fg0x0
  • Updated demo website and made sure it uses the latest from main
  • Updated existing workflows, fuzzer, dependabot, etc., added more tests
  • Bumped several dependencies where possible

v3.4.3

Compare Source


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 9am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels May 18, 2026
@renovate renovate Bot changed the title chore(deps): update dependency dompurify@<3.4.0 to >=3.4.4 chore(deps): update dependency dompurify@<3.4.0 to >=3.4.5 May 18, 2026
@renovate renovate Bot force-pushed the renovate/dompurify-3.4.0-3.x branch from d5d79d1 to fd83b1a Compare May 18, 2026 09:41
@renovate renovate Bot changed the title chore(deps): update dependency dompurify@<3.4.0 to >=3.4.5 chore(deps): update dependency dompurify@<3.4.0 to >=3.4.6 May 26, 2026
@renovate renovate Bot force-pushed the renovate/dompurify-3.4.0-3.x branch from fd83b1a to 08a1738 Compare May 26, 2026 14:10
@renovate renovate Bot changed the title chore(deps): update dependency dompurify@<3.4.0 to >=3.4.6 chore(deps): update dependency dompurify@<3.4.0 to >=3.4.7 May 27, 2026
@renovate renovate Bot force-pushed the renovate/dompurify-3.4.0-3.x branch from 08a1738 to 432b157 Compare May 27, 2026 18:03
@renovate renovate Bot changed the title chore(deps): update dependency dompurify@<3.4.0 to >=3.4.7 chore(deps): update dependency dompurify@<3.4.0 to >=3.4.8 Jun 3, 2026
@renovate renovate Bot force-pushed the renovate/dompurify-3.4.0-3.x branch from 432b157 to 1865479 Compare June 3, 2026 15:52
@sonarqubecloud
Copy link
Copy Markdown

sonarqubecloud Bot commented Jun 3, 2026

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants