[Snyk] Upgrade dompurify from 3.3.0 to 3.3.1#241
Conversation
Snyk has created this PR to upgrade dompurify from 3.3.0 to 3.3.1. See this package in npm: dompurify See this project in Snyk: https://app.snyk.io/org/cognigy-gmbh/project/92bd593a-b4bf-439d-8778-29e930fdd262?utm_source=github&utm_medium=referral&page=upgrade-pr
|
This is a patch upgrade from version 3.3.0 to 3.3.1. According to the release notes, this version contains minor updates to settings and import syntax. It does not introduce any breaking changes. Source: Release notes
|
There was a problem hiding this comment.
Pull request overview
This PR upgrades the dompurify dependency from version 3.3.0 to 3.3.1, a minor patch release that includes bug fixes and improvements to the HTML sanitization library. The update includes fixes for the ADD_FORBID_CONTENTS setting behavior and corrected ESM import syntax.
Changes:
- Updates
dompurifydependency to version 3.3.1 (released December 8, 2025)
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
Lockfile refresh (no package.json change, resolved via existing caret ranges): - @emotion/react 11.14.0, @emotion/styled 11.14.1 - @reduxjs/toolkit 2.2.7 → 2.11.2 - moment 2.30.1, react-hot-toast 2.4.1 → 2.6.0 - react-markdown 9.0.3 → 9.1.0, react-remove-scroll 2.7.2 - remark-gfm 4.0.1, @braintree/sanitize-url 6.0.4 - redux 4.2.1 Pin bumps (patch/minor, same major): - @emotion/serialize 1.3.0 → 1.3.3 - dompurify 3.3.2 → 3.4.0 (supersedes snyk PRs #272, #261, #259, #256, #241, #233) - react-redux 7.2.8 → 7.2.9 (supersedes snyk PRs #242, #234, #36) Socket-client pinned at 5.0.0-beta.26 (current beta; latest tag is 4.9.2). Major bumps deferred: @emotion/cache 10→11, react-redux →9, redux →5, react-responsive →10, react-markdown →10, uuid →13, stylis →4, @braintree/sanitize-url →7. Build passes (UMD + ESM). tsc:check error count unchanged (75, pre-existing).
Lockfile refresh (no package.json change, resolved via existing caret ranges): - @emotion/react 11.14.0, @emotion/styled 11.14.1 - @reduxjs/toolkit 2.2.7 → 2.11.2 - moment 2.30.1, react-hot-toast 2.4.1 → 2.6.0 - react-markdown 9.0.3 → 9.1.0, react-remove-scroll 2.7.2 - remark-gfm 4.0.1, @braintree/sanitize-url 6.0.4 - redux 4.2.1 Pin bumps (patch/minor, same major): - @emotion/serialize 1.3.0 → 1.3.3 - dompurify 3.3.2 → 3.4.0 (supersedes snyk PRs #272, #261, #259, #256, #241, #233) - react-redux 7.2.8 → 7.2.9 (supersedes snyk PRs #242, #234, #36) Socket-client pinned at 5.0.0-beta.26 (current beta; latest tag is 4.9.2). Major bumps deferred: @emotion/cache 10→11, react-redux →9, redux →5, react-responsive →10, react-markdown →10, uuid →13, stylis →4, @braintree/sanitize-url →7. Build passes (UMD + ESM). tsc:check error count unchanged (75, pre-existing).
Snyk has created this PR to upgrade dompurify from 3.3.0 to 3.3.1.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version is 1 version ahead of your current version.
The recommended version was released 2 months ago.
Release notes
Package name: dompurify
-
3.3.1 - 2025-12-08
- Updated
- Updated the ESM import syntax to be more correct, thanks @ binhpv
-
3.3.0 - 2025-10-13
- Added the SVG
- Added support for
- Fixed an issue with the
from dompurify GitHub release notesADD_FORBID_CONTENTSsetting to extend default list, thanks @ MariusRumpfmask-typeattribute to default allow-list, thanks @ prasadrajandranADD_ATTRandADD_TAGSto accept functions, thanks @ nelstromslotelement being in both SVG and HTML allow-list, thanks @ Wim-ValgaerenImportant
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information: