From ed85fc7f245e24c4dfd5b430075c1faf7259879e Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 16 Sep 2024 21:02:07 +0000 Subject: [PATCH] Bump dompurify from 2.4.0 to 2.5.4 in /client Bumps [dompurify](https://github.com/cure53/DOMPurify) from 2.4.0 to 2.5.4. - [Release notes](https://github.com/cure53/DOMPurify/releases) - [Commits](https://github.com/cure53/DOMPurify/compare/2.4.0...2.5.4) --- updated-dependencies: - dependency-name: dompurify dependency-type: direct:production ... Signed-off-by: dependabot[bot] --- client/package.json | 2 +- client/yarn.lock | 8 ++++---- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/client/package.json b/client/package.json index 4cd51d23b..c1f761d6d 100644 --- a/client/package.json +++ b/client/package.json @@ -35,7 +35,7 @@ "chart.js": "^2.9.4", "chartkick": "^3.1.1", "core-js": "3", - "dompurify": "^2.3.3", + "dompurify": "^2.5.4", "dot-prop": "^5.1.1", "es5-shim": "^4.5.13", "font-awesome": "^4.7.0", diff --git a/client/yarn.lock b/client/yarn.lock index 8d3a90efb..6daf045d4 100644 --- a/client/yarn.lock +++ b/client/yarn.lock @@ -6242,10 +6242,10 @@ domhandler@^4.0.0, domhandler@^4.2.0, domhandler@^4.3.1: dependencies: domelementtype "^2.2.0" -dompurify@^2.3.3: - version "2.4.0" - resolved "https://registry.yarnpkg.com/dompurify/-/dompurify-2.4.0.tgz#c9c88390f024c2823332615c9e20a453cf3825dd" - integrity sha512-Be9tbQMZds4a3C6xTmz68NlMfeONA//4dOavl/1rNw50E+/QO0KVpbcU0PcaW0nsQxurXls9ZocqFxk8R2mWEA== +dompurify@^2.5.4: + version "2.5.4" + resolved "https://registry.yarnpkg.com/dompurify/-/dompurify-2.5.4.tgz#347e91070963b22db31c7c8d0ce9a0a2c3c08746" + integrity sha512-l5NNozANzaLPPe0XaAwvg3uZcHtDBnziX/HjsY1UcDj1MxTK8Dd0Kv096jyPK5HRzs/XM5IMj20dW8Fk+HnbUA== domutils@^1.5.1: version "1.7.0"