Skip to content

fix(frontend): bump dompurify to 3.4.13 to fix GHSA-55q2-fjhq-7xh7 - #313

Open
jasergu wants to merge 2 commits into
Open-Legal-Products:mainfrom
jasergu:chore/bump-dompurify-3.4.12
Open

fix(frontend): bump dompurify to 3.4.13 to fix GHSA-55q2-fjhq-7xh7#313
jasergu wants to merge 2 commits into
Open-Legal-Products:mainfrom
jasergu:chore/bump-dompurify-3.4.12

Conversation

@jasergu

@jasergu jasergu commented Aug 12, 2026

Copy link
Copy Markdown

Summary

Bumps dompurify from ^3.4.8 to ^3.4.13 in the frontend to pick up the fix for GHSA-55q2-fjhq-7xh7 (moderate severity): IN_PLACE hook removal leaves a detached subtree executable, causing XSS. All versions <=3.4.12 are affected; the fix landed in 3.4.13.

Changes

  • frontend/package.json: dompurify ^3.4.8^3.4.13
  • frontend/package-lock.json: regenerated accordingly

No code changes required — this is a drop-in patch update.

Verification

  • npm audit no longer reports the dompurify advisory after the bump.

🤖 Generated with Claude Code

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@CLAassistant

CLAassistant commented Aug 12, 2026

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you all sign our Contributor License Agreement before we can accept your contribution.
1 out of 2 committers have signed the CLA.

✅ willchen96
❌ “Jorge”


“Jorge” seems not to be a GitHub user. You need a GitHub account to be able to sign the CLA. If you have already a GitHub account, please add the email address used for this commit to your account.
You have signed the CLA already but the status is still pending? Let us recheck it.

@willchen96

Copy link
Copy Markdown
Collaborator

@jasergu thanks. please sign the CLA

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants