Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade DOMPurify to latest (2.5.4) #2595

Closed
stefan-gheorghe-leica opened this issue Sep 18, 2024 · 4 comments
Closed

Upgrade DOMPurify to latest (2.5.4) #2595

stefan-gheorghe-leica opened this issue Sep 18, 2024 · 4 comments

Comments

@stefan-gheorghe-leica
Copy link

Describe the problem to be solved
We're using redoc-cli and via the redoc npm package it brings up the dompurify 2.2.2. This package contains a vulnerability which got fixed in version >= 2.5.4
image

Describe the solution you'd like
Update used dompurify in redoc to at least 2.5.4

@stefan-gheorghe-leica
Copy link
Author

See related #2581

@AlexVarchuk
Copy link
Collaborator

closed via #2602

@gheorghe-stefan
Copy link

Hi @AlexVarchuk , any news about #2581 ?
Also when we could have a release of redocly including these 2 upgraded packages?
Thanks in advance.

@AlexVarchuk
Copy link
Collaborator

Hi @gheorghe-stefan, dompurify already released but webpack have not merged yet.
I believe webpack author of PR will merge it soon and we have it before the next release.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants