Skip to content

Commit 8769990

Browse files
fix(deps): update dependency sanitize-html to v2 [security]
1 parent e58c8ad commit 8769990

File tree

2 files changed

+58
-50
lines changed

2 files changed

+58
-50
lines changed

packages/gatsby-transformer-remark/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@
2323
"remark-retext": "^4.0.0",
2424
"remark-stringify": "^9.0.1",
2525
"retext-english": "^3.0.4",
26-
"sanitize-html": "^1.27.5",
26+
"sanitize-html": "^2.0.0",
2727
"underscore.string": "^3.3.6",
2828
"unified": "^9.2.2",
2929
"unist-util-remove-position": "^3.0.0",

yarn.lock

Lines changed: 57 additions & 49 deletions
Original file line numberDiff line numberDiff line change
@@ -8380,12 +8380,7 @@ core-js-compat@^3.16.0, core-js-compat@^3.9.1:
83808380
browserslist "^4.16.6"
83818381
semver "7.0.0"
83828382

8383-
core-js-pure@^3.0.0:
8384-
version "3.6.4"
8385-
resolved "https://registry.yarnpkg.com/core-js-pure/-/core-js-pure-3.6.4.tgz#4bf1ba866e25814f149d4e9aaa08c36173506e3a"
8386-
integrity sha512-epIhRLkXdgv32xIUFaaAry2wdxZYBi6bgM7cB136dzzXXa+dFyRLTZeLUJxnd8ShrmyVXBub63n2NHo2JAt8Cw==
8387-
8388-
core-js-pure@^3.8.1:
8383+
core-js-pure@^3.0.0, core-js-pure@^3.8.1:
83898384
version "3.24.1"
83908385
resolved "https://registry.yarnpkg.com/core-js-pure/-/core-js-pure-3.24.1.tgz#8839dde5da545521bf282feb7dc6d0b425f39fd3"
83918386
integrity sha512-r1nJk41QLLPyozHUUPmILCEMtMw24NG4oWK6RbsDdjzQgg9ZvrUsPBj1MnG0wXXp1DCDU6j+wUvEmBSrtRbLXg==
@@ -9702,6 +9697,15 @@ dom-serializer@^1.0.1, dom-serializer@^1.3.2:
97029697
domhandler "^4.2.0"
97039698
entities "^2.0.0"
97049699

9700+
dom-serializer@^2.0.0:
9701+
version "2.0.0"
9702+
resolved "https://registry.yarnpkg.com/dom-serializer/-/dom-serializer-2.0.0.tgz#e41b802e1eedf9f6cae183ce5e622d789d7d8e53"
9703+
integrity sha512-wIkAryiqt/nV5EQKqQpo3SToSOV9J0DnbJqwK7Wv/Trc92zIAYZ4FlMu+JPFW1DfGFt81ZTCGgDEabffXeLyJg==
9704+
dependencies:
9705+
domelementtype "^2.3.0"
9706+
domhandler "^5.0.2"
9707+
entities "^4.2.0"
9708+
97059709
dom-urls@^1.1.0:
97069710
version "1.1.0"
97079711
resolved "https://registry.yarnpkg.com/dom-urls/-/dom-urls-1.1.0.tgz#001ddf81628cd1e706125c7176f53ccec55d918e"
@@ -9717,10 +9721,10 @@ domelementtype@1:
97179721
resolved "https://registry.yarnpkg.com/domelementtype/-/domelementtype-1.3.1.tgz#d048c44b37b0d10a7f2a3d5fee3f4333d790481f"
97189722
integrity sha512-BSKB+TSpMpFI/HOxCNr1O8aMOTZ8hT3pM3GQ0w/mWRmkhEDSFJkkyzz4XQsBV44BChwGkrDfMyjVD0eA2aFV3w==
97199723

9720-
domelementtype@^2.0.1, domelementtype@^2.2.0:
9721-
version "2.2.0"
9722-
resolved "https://registry.yarnpkg.com/domelementtype/-/domelementtype-2.2.0.tgz#9a0b6c2782ed6a1c7323d42267183df9bd8b1d57"
9723-
integrity sha512-DtBMo82pv1dFtUmHyr48beiuq792Sxohr+8Hm9zoxklYPfa6n0Z3Byjj2IV7bmr2IyqClnqEQhfgHJJ5QF0R5A==
9724+
domelementtype@^2.0.1, domelementtype@^2.2.0, domelementtype@^2.3.0:
9725+
version "2.3.0"
9726+
resolved "https://registry.yarnpkg.com/domelementtype/-/domelementtype-2.3.0.tgz#5c45e8e869952626331d7aab326d01daf65d589d"
9727+
integrity sha512-OLETBj6w0OsagBwdXnPdN0cnMfF9opN69co+7ZrbfPGrdpPVNBUj02spi6B1N7wChLQiPn4CSH/zJvXw56gmHw==
97249728

97259729
domexception@^1.0.1:
97269730
version "1.0.1"
@@ -9735,20 +9739,20 @@ domexception@^2.0.1:
97359739
dependencies:
97369740
webidl-conversions "^5.0.0"
97379741

9738-
domhandler@^3.0.0:
9739-
version "3.0.0"
9740-
resolved "https://registry.yarnpkg.com/domhandler/-/domhandler-3.0.0.tgz#51cd13efca31da95bbb0c5bee3a48300e333b3e9"
9741-
integrity sha512-eKLdI5v9m67kbXQbJSNn1zjh0SDzvzWVWtX+qEI3eMjZw8daH9k8rlj1FZY9memPwjiskQFbe7vHVVJIAqoEhw==
9742-
dependencies:
9743-
domelementtype "^2.0.1"
9744-
97459742
domhandler@^4.0.0, domhandler@^4.2.0, domhandler@^4.3.1:
97469743
version "4.3.1"
97479744
resolved "https://registry.yarnpkg.com/domhandler/-/domhandler-4.3.1.tgz#8d792033416f59d68bc03a5aa7b018c1ca89279c"
97489745
integrity sha512-GrwoxYN+uWlzO8uhUXRl0P+kHE4GtVPfYzVLcUxPL7KNdHKj66vvlhiweIHqYYXWlw+T8iLMp42Lm67ghw4WMQ==
97499746
dependencies:
97509747
domelementtype "^2.2.0"
97519748

9749+
domhandler@^5.0.2, domhandler@^5.0.3:
9750+
version "5.0.3"
9751+
resolved "https://registry.yarnpkg.com/domhandler/-/domhandler-5.0.3.tgz#cc385f7f751f1d1fc650c21374804254538c7d31"
9752+
integrity sha512-cgwlv/1iFQiFnU96XXgROh8xTeetsnJiDsTc7TYCLFd9+/WNkIqPTxiM/8pSd8VIrhXGTf1Ny1q1hquVqDJB5w==
9753+
dependencies:
9754+
domelementtype "^2.3.0"
9755+
97529756
dompurify@^2.2.6:
97539757
version "2.2.7"
97549758
resolved "https://registry.yarnpkg.com/dompurify/-/dompurify-2.2.7.tgz#a5f055a2a471638680e779bd08fc334962d11fd8"
@@ -9766,7 +9770,7 @@ domutils@^1.7.0:
97669770
dom-serializer "0"
97679771
domelementtype "1"
97689772

9769-
domutils@^2.0.0, domutils@^2.5.2, domutils@^2.7.0, domutils@^2.8.0:
9773+
domutils@^2.5.2, domutils@^2.7.0, domutils@^2.8.0:
97709774
version "2.8.0"
97719775
resolved "https://registry.yarnpkg.com/domutils/-/domutils-2.8.0.tgz#4437def5db6e2d1f5d6ee859bd95ca7d02048135"
97729776
integrity sha512-w96Cjofp72M5IIhpjgobBimYEfoPjx1Vx0BSX9P30WBdZW2WIKU0T1Bd0kz2eNZ9ikjKgHbEyKx8BB6H1L3h3A==
@@ -9775,6 +9779,15 @@ domutils@^2.0.0, domutils@^2.5.2, domutils@^2.7.0, domutils@^2.8.0:
97759779
domelementtype "^2.2.0"
97769780
domhandler "^4.2.0"
97779781

9782+
domutils@^3.0.1:
9783+
version "3.2.2"
9784+
resolved "https://registry.yarnpkg.com/domutils/-/domutils-3.2.2.tgz#edbfe2b668b0c1d97c24baf0f1062b132221bc78"
9785+
integrity sha512-6kZKyUajlDuqlHKVX1w7gyslj9MPIXzIFiz/rGu35uC1wMi+kMhQwGhl4lt9unC9Vb9INnY9Z3/ZA3+FhASLaw==
9786+
dependencies:
9787+
dom-serializer "^2.0.0"
9788+
domelementtype "^2.3.0"
9789+
domhandler "^5.0.3"
9790+
97789791
dot-case@^2.1.0:
97799792
version "2.1.1"
97809793
resolved "https://registry.yarnpkg.com/dot-case/-/dot-case-2.1.1.tgz#34dcf37f50a8e93c2b3bca8bb7fb9155c7da3bee"
@@ -10025,6 +10038,11 @@ entities@^2.0.0, entities@~2.0.0:
1002510038
resolved "https://registry.yarnpkg.com/entities/-/entities-2.0.0.tgz#68d6084cab1b079767540d80e56a39b423e4abf4"
1002610039
integrity sha512-D9f7V0JSRwIxlRI2mjMqufDrRDnx8p+eEOz7aUM9SuvF8gsBzra0/6tbjl1m8eQHrZlYj6PxqE00hZ1SAIKPLw==
1002710040

10041+
entities@^4.2.0, entities@^4.4.0:
10042+
version "4.5.0"
10043+
resolved "https://registry.yarnpkg.com/entities/-/entities-4.5.0.tgz#5d268ea5e7113ec74c4d033b79ea5a35a488fb48"
10044+
integrity sha512-V0hjH4dGPh9Ao5p0MoRY6BVqtwCjhz6vI5LT8AJ55H+4g9/4vbHx1I54fS0XuclLhDHArPQCiMjDxjaL8fPxhw==
10045+
1002810046
env-paths@^2.2.0:
1002910047
version "2.2.1"
1003010048
resolved "https://registry.npmjs.org/env-paths/-/env-paths-2.2.1.tgz#420399d416ce1fbe9bc0a07c62fa68d67fd0f8f2"
@@ -10061,14 +10079,7 @@ error-ex@^1.2.0, error-ex@^1.3.1:
1006110079
dependencies:
1006210080
is-arrayish "^0.2.1"
1006310081

10064-
error-stack-parser@^2.0.6:
10065-
version "2.0.6"
10066-
resolved "https://registry.yarnpkg.com/error-stack-parser/-/error-stack-parser-2.0.6.tgz#5a99a707bd7a4c58a797902d48d82803ede6aad8"
10067-
integrity sha512-d51brTeqC+BHlwF0BhPtcYgF5nlzf9ZZ0ZIUQNZpc9ZB9qw5IJ2diTrBY9jlCJkTLITYPjmiX6OWCwH+fuyNgQ==
10068-
dependencies:
10069-
stackframe "^1.1.1"
10070-
10071-
error-stack-parser@^2.1.4:
10082+
error-stack-parser@^2.0.6, error-stack-parser@^2.1.4:
1007210083
version "2.1.4"
1007310084
resolved "https://registry.yarnpkg.com/error-stack-parser/-/error-stack-parser-2.1.4.tgz#229cb01cdbfa84440bfa91876285b94680188286"
1007410085
integrity sha512-Sk5V6wVazPhq5MhpO+AUxJn5x7XSXGl1R93Vn7i+zS15KDVxQijejNCrz8340/2bgLBjR9GtEG8ZVKONDjcqGQ==
@@ -12963,16 +12974,6 @@ html-webpack-tags-plugin@^3.0.2:
1296312974
minimatch "^3.0.4"
1296412975
slash "^3.0.0"
1296512976

12966-
htmlparser2@^4.1.0:
12967-
version "4.1.0"
12968-
resolved "https://registry.yarnpkg.com/htmlparser2/-/htmlparser2-4.1.0.tgz#9a4ef161f2e4625ebf7dfbe6c0a2f52d18a59e78"
12969-
integrity sha512-4zDq1a1zhE4gQso/c5LP1OtrhYTncXNSpvJYtWJBtXAETPlMfi3IFNjGuQbYLuVY4ZR0QMqRVvo4Pdy9KLyP8Q==
12970-
dependencies:
12971-
domelementtype "^2.0.1"
12972-
domhandler "^3.0.0"
12973-
domutils "^2.0.0"
12974-
entities "^2.0.0"
12975-
1297612977
htmlparser2@^6.1.0:
1297712978
version "6.1.0"
1297812979
resolved "https://registry.yarnpkg.com/htmlparser2/-/htmlparser2-6.1.0.tgz#c4d762b6c3371a05dbe65e94ae43a9f845fb8fb7"
@@ -12983,6 +12984,16 @@ htmlparser2@^6.1.0:
1298312984
domutils "^2.5.2"
1298412985
entities "^2.0.0"
1298512986

12987+
htmlparser2@^8.0.0:
12988+
version "8.0.2"
12989+
resolved "https://registry.yarnpkg.com/htmlparser2/-/htmlparser2-8.0.2.tgz#f002151705b383e62433b5cf466f5b716edaec21"
12990+
integrity sha512-GYdjWKDkbRLkZ5geuHs5NY1puJ+PXwP7+fHPRz06Eirsb9ugf6d8kkXav6ADhcODhFFPMIXyxkxSuMf3D6NCFA==
12991+
dependencies:
12992+
domelementtype "^2.3.0"
12993+
domhandler "^5.0.3"
12994+
domutils "^3.0.1"
12995+
entities "^4.4.0"
12996+
1298612997
http-basic@^2.5.1:
1298712998
version "2.5.1"
1298812999
resolved "https://registry.yarnpkg.com/http-basic/-/http-basic-2.5.1.tgz#8ce447bdb5b6c577f8a63e3fa78056ec4bb4dbfb"
@@ -19918,7 +19929,7 @@ [email protected]:
1991819929
source-map "^0.5.6"
1991919930
supports-color "^3.2.3"
1992019931

19921-
[email protected], postcss@^7.0.0, postcss@^7.0.1, postcss@^7.0.14, postcss@^7.0.27, postcss@^7.0.32, postcss@^7.0.5:
19932+
[email protected], postcss@^7.0.0, postcss@^7.0.1, postcss@^7.0.14, postcss@^7.0.32, postcss@^7.0.5:
1992219933
version "7.0.36"
1992319934
resolved "https://registry.yarnpkg.com/postcss/-/postcss-7.0.36.tgz#056f8cffa939662a8f5905950c07d5285644dfcb"
1992419935
integrity sha512-BebJSIUMwJHRH0HAQoxN4u1CN86glsrwsW0q7T+/m44eXOUAxSNdHRkNZPYz5vVUbg17hFgOQDE7fZk7li3pZw==
@@ -22616,15 +22627,17 @@ safe-resolve@^1.0.0:
2261622627
version "2.1.2"
2261722628
resolved "https://registry.yarnpkg.com/safer-buffer/-/safer-buffer-2.1.2.tgz#44fa161b0187b9549dd84bb91802f9bd8385cd6a"
2261822629

22619-
sanitize-html@^1.27.5:
22620-
version "1.27.5"
22621-
resolved "https://registry.yarnpkg.com/sanitize-html/-/sanitize-html-1.27.5.tgz#6c8149462adb23e360e1bb71cc0bae7f08c823c7"
22622-
integrity sha512-M4M5iXDAUEcZKLXkmk90zSYWEtk5NH3JmojQxKxV371fnMh+x9t1rqdmXaGoyEHw3z/X/8vnFhKjGL5xFGOJ3A==
22630+
sanitize-html@^2.0.0:
22631+
version "2.17.0"
22632+
resolved "https://registry.yarnpkg.com/sanitize-html/-/sanitize-html-2.17.0.tgz#a8f66420a6be981d8fe412e3397cc753782598e4"
22633+
integrity sha512-dLAADUSS8rBwhaevT12yCezvioCA+bmUTPH/u57xKPT8d++voeYE6HeluA/bPbQ15TwDBG2ii+QZIEmYx8VdxA==
2262322634
dependencies:
22624-
htmlparser2 "^4.1.0"
22625-
lodash "^4.17.15"
22635+
deepmerge "^4.2.2"
22636+
escape-string-regexp "^4.0.0"
22637+
htmlparser2 "^8.0.0"
22638+
is-plain-object "^5.0.0"
2262622639
parse-srcset "^1.0.2"
22627-
postcss "^7.0.27"
22640+
postcss "^8.3.11"
2262822641

2262922642
saslprep@^1.0.0:
2263022643
version "1.0.3"
@@ -23405,11 +23418,6 @@ stack-utils@^2.0.2, stack-utils@^2.0.3:
2340523418
dependencies:
2340623419
escape-string-regexp "^2.0.0"
2340723420

23408-
stackframe@^1.1.1:
23409-
version "1.1.1"
23410-
resolved "https://registry.yarnpkg.com/stackframe/-/stackframe-1.1.1.tgz#ffef0a3318b1b60c3b58564989aca5660729ec71"
23411-
integrity sha512-0PlYhdKh6AfFxRyK/v+6/k+/mMfyiEBbTM5L94D0ZytQnJ166wuwoTYLHFWGbs2dpA8Rgq763KGWmN1EQEYHRQ==
23412-
2341323421
stackframe@^1.3.4:
2341423422
version "1.3.4"
2341523423
resolved "https://registry.yarnpkg.com/stackframe/-/stackframe-1.3.4.tgz#b881a004c8c149a5e8efef37d51b16e412943310"

0 commit comments

Comments
 (0)