Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade trix from 1.3.1 to 2.1.1 #427

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

hanhdt
Copy link
Owner

@hanhdt hanhdt commented May 8, 2024

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 663/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.4
Cross-site Scripting (XSS)
SNYK-JS-TRIX-6814378
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: trix The new version differs by 250 commits.
  • 0c79bcb v2.1.1
  • 1a5c68a Merge pull request #1149 from basecamp/paste-html-sanitize
  • 14bac18 Sanitize HTML content in data-trix-* attributes
  • 1abe3d2 Test attachment content is sanitized
  • 841ff19 Merge pull request #1147 from basecamp/sanitize-noscript
  • 5e03f4a Sanitize noscript to prevent copy and paste XSS
  • 36c7aeb Merge pull request #1146 from basecamp/dependabot/npm_and_yarn/tar-6.2.1
  • c6023ed Bump tar from 6.2.0 to 6.2.1
  • 968ceda v2.1.0
  • bf8f52a Merge pull request #1138 from basecamp/custom-html-block-attributes
  • c1ee6c3 Merge pull request #1140 from basecamp/dependabot/npm_and_yarn/follow-redirects-1.15.6
  • b53531b Bump follow-redirects from 1.15.4 to 1.15.6
  • 54a8cd0 Default to empty HTML attributes
  • d631450 Allow custom HTML attributes in blocks
  • f7e676d Merge pull request #1136 from basecamp/dependabot/npm_and_yarn/ip-1.1.9
  • 8c70ee2 Bump ip from 1.1.8 to 1.1.9
  • 3f22606 v2.0.10
  • e8dec44 Merge pull request #1131 from basecamp/selected-ranges
  • cd9563c Use the target range to insert the replacement text
  • 10573a8 v2.0.9
  • 989ea6d Merge pull request #1130 from basecamp/non-sauce-ci
  • e18a170 Only run test on SauceLabs when SAUCE_ACCESS_KEY is set
  • 053a1a4 Merge pull request #1129 from basecamp/request-render
  • 4f4b54c Request render after inserting replacement text

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Cross-site Scripting (XSS)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants