Skip to content

chore(markdown): update dompurify#7538

Merged
demshy merged 2 commits intodecaporg:mainfrom
domcleal:update-dompurify
Jul 11, 2025
Merged

chore(markdown): update dompurify#7538
demshy merged 2 commits intodecaporg:mainfrom
domcleal:update-dompurify

Conversation

@domcleal
Copy link
Contributor

Summary

Switches to the newer DOMPurify 3.x branch with fix for CVE-2025-26791, as reported by GitHub on repos using Decap and decap-cms-widget-markdown.

The 3.x branch drops MSIE support, which isn't needed in Decap per #674.

Test plan

Verified decap-cms-widget-markdown/src/__tests__/renderer.spec.js is still passing.

Checklist

Please add a x inside each checkbox:

Switch to 3.x branch with fix for CVE-2025-26791. The 3.x branch drops
MSIE support, which isn't needed in Decap.
@domcleal domcleal requested a review from a team as a code owner July 11, 2025 10:33
@domcleal domcleal changed the title chore: update dompurify chore(markdown): update dompurify Jul 11, 2025
@demshy demshy merged commit 8ce98f9 into decaporg:main Jul 11, 2025
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants