Skip to content

Bump bluemonday from v1.0.2 to v1.0.16+ (vulnerability fix) #445

@bhmj

Description

@bhmj

Summary

The current Sentry-go release (v0.13.0) depends on github.com/microcosm-cc/bluemonday@v1.0.2 which contains a vulnerability CVE-2021-42576 rated as Critical.

Please bump up the imported bluemonday version to 1.0.16+ since the vulnerability was fixed as described here.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions