Skip to content

fix(deps): update dependency dompurify to ^3.4.5 (main)#2673

Merged
AndyScherzinger merged 1 commit into
mainfrom
renovate/main-dompurify-3.x
May 19, 2026
Merged

fix(deps): update dependency dompurify to ^3.4.5 (main)#2673
AndyScherzinger merged 1 commit into
mainfrom
renovate/main-dompurify-3.x

Conversation

@renovate

@renovate renovate Bot commented May 19, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
dompurify ^3.4.3^3.4.5 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

cure53/DOMPurify (dompurify)

v3.4.5

Compare Source

v3.4.4: DOMPurify 3.4.4

Compare Source

  • Added the selectedcontent element to default allow-list, thanks @​lukewarlow
  • Added the command and commandfor attributes to default allowed-list, thanks @​lukewarlow
  • Added better template scrubbing for IN_PLACE operations, thanks @​DEMON1A
  • Added stronger checks for cross-realm windows, thanks @​DEMON1A & @​fg0x0
  • Updated demo website and made sure it uses the latest from main
  • Updated existing workflows, fuzzer, dependabot, etc., added more tests
  • Bumped several dependencies where possible

Configuration

📅 Schedule: (in timezone Europe/Berlin)

  • Branch creation
    • "every weekend"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot requested review from blizzz and enjeck as code owners May 19, 2026 16:42
@renovate renovate Bot added 3. to review Waiting for reviews dependencies Pull requests that update a dependency file labels May 19, 2026
@renovate

renovate Bot commented May 19, 2026

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: package-lock.json

npm --before could not be enforced because existing locked packages were published after the minimumReleaseAge cutoff. This will resolve after the next lock file maintenance run.

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@renovate renovate Bot force-pushed the renovate/main-dompurify-3.x branch from afb646a to 7488471 Compare May 19, 2026 20:04
@AndyScherzinger AndyScherzinger added this to the v2.2.0 milestone May 19, 2026
@AndyScherzinger AndyScherzinger merged commit b414d8f into main May 19, 2026
42 of 46 checks passed
@AndyScherzinger AndyScherzinger deleted the renovate/main-dompurify-3.x branch May 19, 2026 21:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review Waiting for reviews dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant