Skip to content

dompurify version update#3320

Open
jwkk1 wants to merge 1 commit intonhn:masterfrom
jwkk1:master
Open

dompurify version update#3320
jwkk1 wants to merge 1 commit intonhn:masterfrom
jwkk1:master

Conversation

@jwkk1
Copy link
Copy Markdown

@jwkk1 jwkk1 commented Nov 13, 2025

address known prototype pollution and XSS bypass
vulnerabilities

@aedart
Copy link
Copy Markdown

aedart commented Apr 24, 2026

I too could really use this patch. Also, if its not too demanding, perhaps consider using peerDependencies to allow developers update nested dependencies?
In any case, a patch is really needed in this case. The vulnerabilities keep piling up for projects that "embed" dependencies. It's difficult (or sometimes impossible) to force use up-to-date dependencies that are included in the distributed files.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants