Skip to content

fix(deps): bump dompurify from 3.4.13 to 3.4.16 - #832

Merged
d-oit merged 1 commit into
mainfrom
dependabot/npm_and_yarn/dompurify-3.4.16
Oct 2, 2026
Merged

d-oit merged 1 commit into
mainfrom
dependabot/npm_and_yarn/dompurify-3.4.16

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Bumps dompurify from 3.4.13 to 3.4.16.

Release notes

Sourced from dompurify's releases.

DOMPurify 3.4.16

  • Fixed a problem with IN_PLACE node removal when working with hooks, thanks @​manus-pi
  • Fixed a problem with IN_PLACE sanitization and raw-text roots, thanks @​h-t-m
  • Fixed a problem with ESM default exports landing in CommonJS declarations, thanks @​ssi02014
  • Migrated from rollup to rolldown because performance, thanks @​ssi02014
  • Bumped several dependencies where possible

DOMPurify 3.4.15

  • Added better clobbering hardening when XML content is involved, thanks @​gnyselcuk
  • Added several smaller hardening and edge-case improvements, thanks @​leechristensen
  • Bumped several dependencies where possible

DOMPurify 3.4.14

  • Fixed an issue with possible bypasses when risky tags are allow-listed, thanks @​AlirezaRouhbakhsh
  • Fixed a couple of edge cases with mixed document contexts, thanks @​fishjojo1
  • Added the SVG pointer-events and vector-effect presentation attributes to the allow-list, thanks @​Jaybhade
  • Conducted another refactoring run, removed dead branches and duplicated logic, flattened attribute validation
  • Updated the documentation in several spots, README, wiki, etc., thanks @​Akokonunes
  • Updated several development dependencies and CI workflow actions
Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 29, 2026
@vercel

vercel Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
do-knowledge-studio Ready Ready Preview, v0 Oct 2, 2026 12:58pm UTC

@github-actions

github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Blocked merge diagnosis — blocked
⏳ Check run(s) still in progress: ["Codacy Static Code Analysis","GitHub Actions Workflow Validation","Detect Changes","Diagnose Blocked Merge State","commitlint","Dependency Advisory Audit","Secret Detection","Trivy Filesystem Security Scan","Shell Script Security Analysis","Infrastructure as Code Security","labeler"]

@codacy-production

Copy link
Copy Markdown
Contributor

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 0 complexity · 0 duplication

Metric Results
Complexity 0
Duplication 0

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@nexus-check

nexus-check Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor
Akon Labs

GitNexus Review · PR #832

No issues found in 2 changed files. (target branch indexed; the incoming branch is not, so cross-branch structure came from the diff alone)

Summary

A narrowly scoped dependency update with no traced downstream reach. The reported file risk is medium.

🟡 MEDIUM blast radius. This updates dompurify from 3.4.13 to 3.4.16 in package.json and pnpm-lock.yaml, with no graph-traced dependents.

The graph reports no affected flows, and the change touches only these dependency files. Review the declared dependency and its resolved lockfile entry together.

Full detail lives in the GitNexus check run for this commit.

@nexus-check

nexus-check Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

🤖 Agent context for GitNexus Review · PR #832

This comment carries deterministic graph detail for coding agents and reviewers who want the receipts — the main review comment carries the human summary.

🟡 MEDIUM blast radius — no downstream dependents were found in the code graph; a spot-check of the dependents should cover it. (likely driven by file-risk heuristics — no direct dependents or affected modules were found)

Blast Level Dependents Modules Files
🟡 MEDIUM 0 0 2

What changed

Changed Files (2)
File Status
package.json 🟡 modified
pnpm-lock.yaml 🟡 modified

What to check

File Risk (2)
File Risk Category
package.json 🟡 MEDIUM Dependencies
pnpm-lock.yaml 🟢 LOW Lock File

Bumps [dompurify](https://github.com/cure53/DOMPurify) from 3.4.13 to 3.4.16.
- [Release notes](https://github.com/cure53/DOMPurify/releases)
- [Commits](cure53/DOMPurify@3.4.13...3.4.16)

---
updated-dependencies:
- dependency-name: dompurify
  dependency-version: 3.4.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/dompurify-3.4.16 branch from 1ae43e9 to 4f90f20 Compare October 2, 2026 12:55
@d-oit
d-oit merged commit f6033c3 into main Oct 2, 2026
26 checks passed
@d-oit
d-oit deleted the dependabot/npm_and_yarn/dompurify-3.4.16 branch October 2, 2026 18:07

This branch was successfully deployed

1 active deployment
Preview — 4f90f20c Deployed Oct 2, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

config dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant