Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Rollback to dompurify v2 for legacy support #6201

Merged
merged 2 commits into from
Oct 14, 2024

Conversation

thornbill
Copy link
Member

Changes
dompurify v3 removed legacy browser support. v2 is still receiving security updates so we should use it instead of an outdated version of v3.

Issues
Fixes known CVEs
Closes #6077
Closes #6076

@thornbill thornbill added security This PR or issue mainly concerns security dependencies Pull requests that update a dependency file npm labels Oct 14, 2024
@thornbill thornbill added this to the v10.10.0 milestone Oct 14, 2024
@thornbill thornbill requested a review from a team as a code owner October 14, 2024 16:32
@jellyfin-bot
Copy link
Collaborator

jellyfin-bot commented Oct 14, 2024

Cloudflare Pages deployment

Latest commit 016fc1f
Status ✅ Deployed!
Preview URL https://eed34298.jellyfin-web.pages.dev
Type 🔀 Preview

View build logs

Copy link
Member

@ferferga ferferga left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Shouldn't it be also excluded from renovate config?

Copy link

sonarcloud bot commented Oct 14, 2024

@thornbill
Copy link
Member Author

Yeah good call @ferferga... better to handle that properly than deal with closing the PR all the time 😅

@thornbill thornbill merged commit fbb8687 into jellyfin:master Oct 14, 2024
14 checks passed
@thornbill thornbill deleted the dompurify-2 branch October 14, 2024 18:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file npm security This PR or issue mainly concerns security
Projects
Status: Done
Development

Successfully merging this pull request may close these issues.

3 participants