Skip to content

Update dependency dompurify to v3.4.16 - #2230

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/dompurify-3.x-lockfile
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/dompurify-3.x-lockfile

Conversation

@renovate

@renovate renovate Bot commented Aug 23, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
dompurify 3.4.11 → 3.4.16 age confidence

Release Notes

cure53/DOMPurify (dompurify)

v3.4.16: DOMPurify 3.4.16

Compare Source

  • Fixed a problem with IN_PLACE node removal when working with hooks, thanks @​manus-pi
  • Fixed a problem with IN_PLACE sanitization and raw-text roots, thanks @​h-t-m
  • Fixed a problem with ESM default exports landing in CommonJS declarations, thanks @​ssi02014
  • Migrated from rollup to rolldown because performance, thanks @​ssi02014
  • Bumped several dependencies where possible

v3.4.15: DOMPurify 3.4.15

Compare Source

  • Added better clobbering hardening when XML content is involved, thanks @​gnyselcuk
  • Added several smaller hardening and edge-case improvements, thanks @​leechristensen
  • Bumped several dependencies where possible

v3.4.14: DOMPurify 3.4.14

Compare Source

  • Fixed an issue with possible bypasses when risky tags are allow-listed, thanks @​AlirezaRouhbakhsh
  • Fixed a couple of edge cases with mixed document contexts, thanks @​fishjojo1
  • Added the SVG pointer-events and vector-effect presentation attributes to the allow-list, thanks @​Jaybhade
  • Conducted another refactoring run, removed dead branches and duplicated logic, flattened attribute validation
  • Updated the documentation in several spots, README, wiki, etc., thanks @​Akokonunes
  • Updated several development dependencies and CI workflow actions

v3.4.13: DOMPurify 3.4.13

Compare Source

  • Fixed an issue with hook removal during IN_PLACE sanitization, thanks @​koyokr
  • Fixed an issue with hooks potentially bypassing the clone guard, thanks @​AkshayjainG
  • Fixed an issue with DOM clobbering via ownerDocument during IN_PLACE, thanks @​AkshayjainG
  • Bumped several dependencies where possible

v3.4.12: DOMPurify 3.4.12

Compare Source

  • Fixed an issue where a hook would not get called for custom elements, thanks @​Rikuxx0
  • Hardened the handling of hooks removing elements, @​mkrause-bee360
  • Added support for a few new SVG attributes, thanks @​cbn-falias & @​Develop-KIM
  • Hardened the handling of declarative partial updates
  • Updated the documentation is several spots, README, wiki, etc.
  • Bumped several dependencies where possible

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "after 9pm on sunday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@bolt-new-by-stackblitz

Copy link
Copy Markdown

Review PR in StackBlitz Codeflow Run & review this pull request in StackBlitz Codeflow.

@socket-security

socket-security Bot commented Aug 23, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updateddompurify@​3.4.13 ⏵ 3.4.16100 +11001009570

View full report

@github-actions

github-actions Bot commented Aug 23, 2026 •

Copy link
Copy Markdown
Contributor
Project Preview URL1 Manage
Limber https://renovate-dompurify-3-x-lockf.limber-glimdown.pages.dev on Cloudflare
Tutorial https://renovate-dompurify-3-x-lockf.limber-glimmer-tutorial.pages.dev on Cloudflare

Logs

Footnotes

  1. if these branch preview links are not working, please check the logs for the commit-based preview link. There is a character limit of 28 for the branch subdomain, as well as some other heuristics, described here for the sake of implementation ease in deploy-preview.yml, that algo has been omitted. The URLs are logged in the wrangler output, but it's hard to get outputs from a matrix job. ↩

@renovate
renovate Bot force-pushed the renovate/dompurify-3.x-lockfile branch from 0150ef0 to 1fe2963 Compare August 30, 2026 22:08
@renovate renovate Bot changed the title chore(deps): update dependency dompurify to v3.4.14 Update dependency dompurify to v3.4.14 Aug 30, 2026
@renovate
renovate Bot force-pushed the renovate/dompurify-3.x-lockfile branch 2 times, most recently from b992796 to 8063c50 Compare September 13, 2026 21:10
@renovate renovate Bot changed the title Update dependency dompurify to v3.4.14 Update dependency dompurify to v3.4.15 Sep 13, 2026
@renovate
renovate Bot force-pushed the renovate/dompurify-3.x-lockfile branch from 8063c50 to d320736 Compare September 27, 2026 22:02
@renovate renovate Bot changed the title Update dependency dompurify to v3.4.15 Update dependency dompurify to v3.4.16 Sep 27, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants