|
| Summary: |
Upgrade to dompurify 3.2.4 |
| Issue Type: |
Task |
| Affects Versions: |
0.14 |
| Assignee: |
Unassigned |
| Components: |
Dependency Upgrades |
| Created: |
31/Jan/25 10:32 |
| Priority: |
Major |
| Reporter: |
Manuel Leduc |
| Description: |
v3.2.4: DOMPurify 3.2.4 Compare Source
- Fixed a conditional and config dependent mXSS-style bypass reported by @nsysean
- Added a new feature to allow specific hook removal, thanks @davecardwell
- Added purify.js and purify.min.js to exports, thanks @Aetherinox
- Added better logic in case no window object is president, thanks @yehuya
- Updated some dependencies called out by dependabot
- Updated license files etc to show the correct year
|
|