chore(deps): bump sanitize-html from 2.13.0 to 2.17.7 - #4549
dependabot[bot] wants to merge 1 commit into
Conversation
PR SummaryMedium Risk Overview This is a dependency-only change—no application source edits. The newer release pulls in security fixes for XSS and allowlist bypasses in HTML sanitization, which matters because integrations use this library when normalizing content from channels like Discourse, Slack, and Reddit. Note that Reviewed by Cursor Bugbot for commit cd90878. Bugbot is set up for automated code reviews on this repo. Configure here. |
|
|
|
Your PR title doesn't contain a Jira issue key. Consider adding it for better traceability. Example:
Projects:
Please add a Jira issue key to your PR title. |
e2f4aed to
faecfba
Compare
1cea865 to
00b25d3
Compare
Bumps [sanitize-html](https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html) from 2.13.0 to 2.17.7. - [Changelog](https://github.com/apostrophecms/apostrophe/blob/main/packages/sanitize-html/CHANGELOG.md) - [Commits](https://github.com/apostrophecms/apostrophe/commits/sanitize-html@2.17.7/packages/sanitize-html) --- updated-dependencies: - dependency-name: sanitize-html dependency-version: 2.17.7 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
00b25d3 to
cd90878
Compare
Bumps sanitize-html from 2.13.0 to 2.17.7.
Changelog
Sourced from sanitize-html's changelog.
... (truncated)
Commits
72f4531Latest reconciliation q2 m3 2026 (#5555)207846aready for 4.32.0 release (#5513)f820033Latest reconciliation q2 m2 (#5511)2427508release and changelog edits (#5465)5a88e96Latest security q2 (#5464)958d162merge main to latest (#5460)e9b0ab0release only (changelogs formatted) (#5408)f03fa5bLatest security merge (#5407)96cf174For release only (#5381)7ca2d16Merge commit from fork