-
Notifications
You must be signed in to change notification settings - Fork 1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update dependency prismjs to v1.27.0 [SECURITY] #724
base: master
Are you sure you want to change the base?
Conversation
This pull request is being automatically deployed with Vercel (learn more). 🔍 Inspect: https://vercel.com/elliottsj/elliott-dev/J2eYtLc5rURfyb2tnth665NKGAPb |
fd166dd
to
41d2ea7
Compare
The latest updates on your projects. Learn more about Vercel for Git ↗︎
|
41d2ea7
to
c67ce82
Compare
c67ce82
to
beb19da
Compare
beb19da
to
2967332
Compare
2967332
to
68ec24e
Compare
68ec24e
to
ae13b4d
Compare
ae13b4d
to
bb145ce
Compare
bb145ce
to
baa249d
Compare
baa249d
to
8e423d7
Compare
8e423d7
to
93e24e8
Compare
93e24e8
to
584c40c
Compare
584c40c
to
92e69ff
Compare
92e69ff
to
ef4a6f9
Compare
ef4a6f9
to
984dd7a
Compare
af02aec
to
9d6923e
Compare
9d6923e
to
8ff5fd6
Compare
8ff5fd6
to
ee456ae
Compare
ee456ae
to
5c95adc
Compare
5c95adc
to
9d1279a
Compare
9d1279a
to
0ed6201
Compare
0ed6201
to
3e606de
Compare
Deployment failed with the following error:
|
3e606de
to
79aa0da
Compare
79aa0da
to
6417f8c
Compare
6417f8c
to
7cdc4ed
Compare
7cdc4ed
to
5deed92
Compare
5deed92
to
fd7559c
Compare
fd7559c
to
faf5cd8
Compare
faf5cd8
to
f0287b5
Compare
This PR contains the following updates:
1.25.0
->1.27.0
GitHub Vulnerability Alerts
CVE-2022-23647
Impact
Prism's Command line plugin can be used by attackers to achieve an XSS attack. The Command line plugin did not properly escape its output, leading to the input text being inserted into the DOM as HTML code.
Server-side usage of Prism is not impacted. Websites that do not use the Command Line plugin are also not impacted.
Patches
This bug has been fixed in v1.27.0.
Workarounds
Do not use the Command line plugin on untrusted inputs, or sanitized all code blocks (remove all HTML code text) from all code blocks that use the Command line plugin.
References
Release Notes
PrismJS/prism (prismjs)
v1.27.0
Compare Source
New components
3f8cc5a0
Updated components
bcb2e2c8
section
fromkeyword
toselector
(#3305)e46501b9
header
forsection
(#3304)deb3a97f
8458c41f
$
(#3320)d6c53726
441a1422
operator
forpunctuation
(#3306)2eb89e15
Updated plugins
e002e78c
1784b175
82d0ca15
Other
2cc4660b
v1.26.0
Compare Source
New components
b5a70e4c
8476a9ab
d908e457
ec25ba65
ef53f021
Updated components
\d
for[0-9]
(#3097)9fe2f93e
929c33e0
class-name
standard token (#3182)9f5e511d
fa540ab7
ino
alias (#2990)5b7ce5e4
c7809285
node
to known commands (#3291)4b19b502
vcpkg
command (#3282)b351bc69
docker
andpodman
commands (#3237)8c5ed251
d7017beb
variable
and minor improvements (#3186)4cebf34c
directive
greedy (#3112)5c412cbb
char
token (#3207)d85a64ae
char
token (#3270)220bc40f
9ed4cf6e
char
token (#3188)1c88c7da
7b34e65d
a943f2bb
2f9672aa
51e3ecc0
symbol
token name (#3195)6af8a644
dafdbdec
e1370357
532212b2
property
forkey
; alias withattr-name
(#3272)bee6ad56
builtin
name (#3198)6add768b
736c581d
336edeea
char
token (#3271)b58cd722
ee7ab563
operator
token and added tests (#3114)d359eeae
char
token and improvedstring
andnumber
tokens (#3208)f11b86e2
8494519e
symbol
alias for filter names (#3210)3d410670
005ba469
f41bcf23
81920b62
3362fc79
22d0c6ba
0f1b5810
3d708b97
15cb3b78
c2afa59b
5af16014
char
token (#3217)0a9f909c
fa55492b
cfb2e782
number
pattern (#3149)5a24cbff
3b2238fa
dfbb2020
233415b8
23d9aec1
char
token (#3223)3a876df0
baa95cab
char
token and improved string interpolation (#3225)563cd73e
6b168a3b
05e7ab04
defun
(#3130)e8f84a6c
21a3c2d7
00f77a2c
e9b856c8
c6574e6b
c1025aa6
642d93ec
7b72e0ad
char
token and made some tokens greedy (#3231)2334b4b6
75331bea
5bf6e35f
dc1e808f
comment
greedy (#3234)969f152a
adcc8784
55583fb2
string
token (#3235)8e0e95f3
7bcc5da0
314d6994
a3905c04
f053af13
boolean
token (#3248)a5b6c5eb
f22ea9f9
ee62a080
scope
andthis
(#3243)59ef51db
e7ba877b
5688f487
data-type
alternative (#3122)eeb13996
d30a2da6
5ee8c557
bacf9ae3
0390e644
asm
token (#3123)f3b25786
comment
greedy (#3249)8ecef306
match
andcase
(soft) keywords (#3142)3f24dc72
18bd101c
2c63efa6
string
greedy (#3250)1e6dcb51
18c92048
parameter
token (#3090)0a313f4f
809af0d9
4dde2e20
ede55b2c
char
token (#3252)2069ab0c
86028adb
type-definition
and use standard tokens correctly (#3253)4049e5c6
char
token (#3254)7d740c45
4eb81fa1
char
token (#3255)a7bb3001
boolean
token (#3100)51382524
acc0bc09
4e00cddd
char
token (#3256)58a65bfd
afd77ed1
d04d166d
isolated
keyword (#3174)18c828a6
3ef71533
regex
token (#3257)c56e4bf5
e03a7c24
91060fd6
599e30ee
char
token (#3260)e4373256
43124129
aa73d448
a28a86ad
ffd8343f
deed35e3
char
token (#3264)c3f9fb70
09a0e2ba
Updated plugins
d38592c5
drop-tokens
option class (#3166)b679cfe6
highlightLines
function asPrism.plugins.highlightLines
(#3086)9f4c0e74
z-index
of.toolbar
to 10 (#3163)1cac3559
Updated themes
z-index
to make shadows visible in colored table cells (#3161)79f250f3
a6a4ce7e
Other
setLanguage
util function (#3167)b631949a
a80a68ba
disableWorkerMessageHandler
(#3088)213cf7be
.html.test
files for replace.js
language tests (#3148)2e834c8c
5333e281
TestCaseFile
class and generalizedrunTestCase
(#3147)ae8888a0
344d0b27
a394a14d
2f7f7364
package.json
: Addedengines.node
field (#3108)798ee4f6
package(-lock).json
(#3098)8daebb4a
[email protected]
(#3091)e6e1d5ae
d63d6c0e
6f1d904a
6c21b2f7
9d5424b6
cefccdd1
0ecdbdce
4433d7fe
746da79b
ebd59e32
37551200
31b4c1b8
ea361e5a
c5629706
faedfe85
3d96eedc
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.