[Snyk] Upgrade: argon2-browser, bourbon, chai, dompurify, handlebars, jquery, marked, morphdom #130
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade multiple dependencies.
👯 The following dependencies are linked and will therefore be updated together.ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
argon2-browser
from 1.15.4 to 1.18.0 | 3 versions ahead of your current version | 3 years ago
on 2021-06-05
bourbon
from 7.2.0 to 7.3.0 | 1 version ahead of your current version | 2 years ago
on 2023-01-23
chai
from 4.3.6 to 4.5.0 | 7 versions ahead of your current version | 2 months ago
on 2024-07-25
dompurify
from 2.3.6 to 2.5.6 | 23 versions ahead of your current version | 2 months ago
on 2024-07-05
handlebars
from 4.7.7 to 4.7.8 | 1 version ahead of your current version | a year ago
on 2023-08-01
jquery
from 3.6.0 to 3.7.1 | 6 versions ahead of your current version | a year ago
on 2023-08-28
marked
from 4.0.12 to 4.3.0 | 23 versions ahead of your current version | a year ago
on 2023-03-22
morphdom
from 2.6.1 to 2.7.4 | 6 versions ahead of your current version | 2 months ago
on 2024-07-19
Issues fixed by the recommended upgrade:
SNYK-JS-DOMPURIFY-6474511
Release notes
Package name: argon2-browser
-
1.18.0 - 2021-06-05
-
1.17.0 - 2021-05-31
-
1.16.0 - 2021-05-26
-
1.15.4 - 2021-03-31
from argon2-browser GitHub release notes1.18.0
1.17.0
1.16.0
1.15.4
Package name: bourbon
-
7.3.0 - 2023-01-23
-
7.2.0 - 2022-02-22
- Reverted:
from bourbon GitHub release notesUpdate initializers so they only include assets for >=Rails 5. Dropped support for <Rails 5.
What's Changed
For context see : #1106 (comment)
Package name: chai
-
4.5.0 - 2024-07-25
- Update type detect (#1631) 1a36d35
- Update type detect by @ koddsson in #1631
-
4.4.1 - 2024-01-12
- fix: removes
-
4.4.0 - 2024-01-05
- Allow deepEqual fonction to be configured globally (4.x.x branch) by @ forty in #1553
-
4.3.10 - 2023-09-28
-
4.3.9 - 2023-09-27
-
4.3.8 - 2023-08-24
-
4.3.7 - 2022-11-07
-
4.3.6 - 2022-01-26
from chai GitHub release notesv4.4.1...v4.5.0
What's Changed
Full Changelog: v4.4.1...v4.5.0
What's Changed
??for node compat by @ 43081j in #1574Full Changelog: v4.4.0...v4.4.1
What's Changed
Full Changelog: v4.3.10...v4.4.0
Package name: dompurify
-
2.5.6 - 2024-07-05
- Fixed an issue with the execution logic of attribute hooks to prevent bypasses, thanks @ kevin-mizu
- Fixed a minor problem with the bower file pointing to the wrong dist path
- Updated several development dependencies
-
2.5.5 - 2024-05-31
- Fixed a minor issue with the dist paths in
- Fixed a minor issue with sanitizing HTML coming from copy&paste Word content, thanks @ kakao-bishop-cho
-
2.5.4 - 2024-05-20
- Fixed a bug with latest
- Fixed the tests for MSIE and fixed related test-runner
-
2.5.3 - 2024-05-11
- Fixed several mXSS variations found by and thanks to @ kevin-mizu & @ Ry0taK
- Added better configurability for comment scrubbing default behavior
- Added better hardening against Prototype Pollution attacks, thanks @ kevin-mizu
- Fixed some smaller issues in README and other documentation
-
2.5.2 - 2024-04-30
- Addressed and fixed a mXSS variation found by @ kevin-mizu
- Addressed and fixed a mXSS variation found by Adam Kues of Assetnote
- Updated tests for older Safari and Chrome versions
-
2.5.1 - 2024-04-26
-
2.5.0 - 2024-04-07
-
2.4.9 - 2024-03-21
-
2.4.8 - 2024-03-19
-
2.4.7 - 2023-07-11
-
2.4.6 - 2023-07-10
-
2.4.5 - 2023-03-01
-
2.4.4 - 2023-02-13
-
2.4.3 - 2023-01-06
-
2.4.2 - 2023-01-05
-
2.4.1 - 2022-11-10
-
2.4.0 - 2022-08-24
-
2.3.12 - 2022-08-23
-
2.3.11 - 2022-08-23
-
2.3.10 - 2022-07-18
-
2.3.9 - 2022-07-11
-
2.3.8 - 2022-05-13
-
2.3.7 - 2022-05-11
-
2.3.6 - 2022-02-16
from dompurify GitHub release notesbower.js, thanks @ HakumenNCisNaNchecks affecting MSIE, thanks @ tulachPackage name: handlebars
-
4.7.8 - 2023-08-01
- Make library compatible with workers (#1894) - 3d3796c
- Don't rely on Node.js global object (#1776) - 2954e7e
- Fix compiling of each block params in strict mode (#1855) - 30dbf04
- Fix rollup warning when importing Handlebars as ESM - 03d387b
- Fix bundler issue with webpack 5 (#1862) - c6c6bbb
- Use https instead of git for mustache submodule - 88ac068
-
4.7.7 - 2021-02-15
from handlebars GitHub release notesCommits
v4.7.7
Package name: jquery
-
3.7.1 - 2023-08-28
-
3.7.0 - 2023-05-11
-
3.6.4 - 2023-03-08
-
3.6.3 - 2022-12-20
-
3.6.2 - 2022-12-13
-
3.6.1 - 2022-08-26
-
3.6.0 - 2021-03-02
from jquery GitHub release noteshttps://blog.jquery.com/2023/08/28/jquery-3-7-1-released-reliable-table-row-dimensions/
https://blog.jquery.com/2023/05/11/jquery-3-7-0-released-staying-in-order/
https://blog.jquery.com/2023/03/08/jquery-3-6-4-released-selector-forgiveness/
https://blog.jquery.com/2022/12/20/jquery-3-6-3-released-a-quick-selector-fix/
https://blog.jquery.com/2022/12/13/jquery-3-6-2-released/
https://blog.jquery.com/2022/08/26/jquery-3-6-1-maintenance-release/
https://blog.jquery.com/2021/03/02/jquery-3-6-0-released/
Package name: marked
-
4.3.0 - 2023-03-22
- always return promise if async (#2728) (042dcc5)
- fenced code doesn't need a trailing newline (#2756) (3acbb7f)
- add preprocess and postprocess hooks (#2730) (9b452bc)
-
4.2.12 - 2023-01-14
- revert to build script in ci (d2ab474)
-
4.2.11 - 2023-01-14
- just build in version (22ac2cf)
-
4.2.10 - 2023-01-14
- use version (fd759b3)
-
4.2.9 - 2023-01-14
- fix version (96380c3)
-
4.2.8 - 2023-01-14
- build in postversion for build file version (60c3b7f)
-
4.2.7 - 2023-01-14
- fix build file version (94fa76f)
-
4.2.6 - 2023-01-14
- add version to build files (79b8c0b)
-
4.2.5 - 2022-12-23
- fix paragraph continuation after block element (#2686) (1bbda68)
- fix tabs at beginning of list items (#2679) (e692634)
-
4.2.4 - 2022-12-07
- loose list items are loose (#2672) (df4eb0e)
- remove quotes at the end of gfm autolink (#2673) (697ac2a)
- use paragraph token in blockquote in list (#2671) (edc857c)
-
4.2.3 - 2022-11-20
-
4.2.2 - 2022-11-05
-
4.2.1 - 2022-11-02
-
4.2.0 - 2022-10-31
-
4.1.1 - 2022-10-01
-
4.1.0 - 2022-08-30
-
4.0.19 - 2022-08-21
-
4.0.18 - 2022-07-11
-
4.0.17 - 2022-06-13
-
4.0.16 - 2022-05-17
-
4.0.15 - 2022-05-02
-
4.0.14 - 2022-04-11
-
4.0.13 - 2022-04-08
-
4.0.12 - 2022-01-27
from marked GitHub release notes4.3.0 (2023-03-22)
Bug Fixes
Features
4.2.12 (2023-01-14)
Sorry for all of the quick releases. We were testing out different ways to build the files for releases. v4.2.5 - v4.2.12 have no changes to how marked works. The only addition is the version number in the comment in the build files.
Bug Fixes
4.2.11 (2023-01-14)
Bug Fixes
4.2.10 (2023-01-14)
Bug Fixes
4.2.9 (2023-01-14)
Bug Fixes
4.2.8 (2023-01-14)
Bug Fixes
4.2.7 (2023-01-14)
Bug Fixes
4.2.6 (2023-01-14)
Bug Fixes
4.2.5 (2022-12-23)
Bug Fixes
4.2.4 (2022-12-07)
Bug Fixes
Package name: morphdom
-
2.7.4 - 2024-07-19
-
2.7.3 - 2024-06-20
-
2.7.2 - 2024-01-17
-
2.7.1 - 2023-10-04
-
2.7.0 - 2023-01-31
-
2.6.2 - 2023-01-30
-
2.6.1 - 2020-05-05
from morphdom GitHub release notesVersion 2.7.4
Version 2.7.3
Version 2.7.2
Verison 2.7.1
Version 2.7.0
2.6.1
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information: