Skip to content

Bump bluemonday to silence the security alert#4607

Merged
mislav merged 2 commits intotrunkfrom
bluemonday-security
Oct 25, 2021
Merged

Bump bluemonday to silence the security alert#4607
mislav merged 2 commits intotrunkfrom
bluemonday-security

Conversation

@mislav
Copy link
Contributor

@mislav mislav commented Oct 25, 2021

GitHub CLI is not affected by GHSA-x95h-979x-cf3j, since we are not vulnerable to XSS via HTML injection, but upgrading the library might silence the security alert.

bluemonday is a transitive dependency via glamour https://github.com/charmbracelet/glamour/blob/86a99924d7f6f13bda4abdd2dbec7bf4cf5df23e/ansi/context.go#L26

GitHub CLI is not affected by GHSA-x95h-979x-cf3j, since we are not
vulnerable to XSS via HTML injection, but upgrading the library might
silence the security alert.
@mislav mislav requested a review from a team as a code owner October 25, 2021 16:42
@mislav mislav requested review from vilmibm and removed request for a team October 25, 2021 16:42
@mislav mislav merged commit cbd6569 into trunk Oct 25, 2021
@mislav mislav deleted the bluemonday-security branch October 25, 2021 17:43
@VictorBatta VictorBatta mentioned this pull request Dec 4, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants