Skip to content

fix: resolve dompurify v3.4.11 package vulnerability#2148

Open
yassinedorbozgithub wants to merge 1 commit into
mainfrom
fix/security-dompurify-v3-4-11
Open

fix: resolve dompurify v3.4.11 package vulnerability#2148
yassinedorbozgithub wants to merge 1 commit into
mainfrom
fix/security-dompurify-v3-4-11

Conversation

@yassinedorbozgithub

Copy link
Copy Markdown
Collaborator

Summary

Updated the dompurify dependency to v3.4.11 to address a known security vulnerability. This change only upgrades the package version without introducing application logic changes.

Why

Keeping dependencies up to date helps mitigate known security risks and ensures the project remains compliant with security best practices.

How to review

  • Verify that dompurify has been upgraded to v3.4.11.
  • Confirm there are no unintended dependency or lockfile changes beyond the version update.
  • Review that no application behavior has changed as a result of the upgrade.

Validation

  • Verified the project installs successfully with the updated dependency.
  • Confirmed the application builds and runs successfully.
  • Checked that the reported dompurify vulnerability is resolved.

@yassinedorbozgithub yassinedorbozgithub self-assigned this Jul 23, 2026
@yassinedorbozgithub yassinedorbozgithub added the security Vulnerabilities, exploits, sensitive data label Jul 23, 2026
@yassinedorbozgithub yassinedorbozgithub changed the title fix: resolve dompurify v 3.4.11 package vulnerability fix: resolve dompurify v3.4.11 package vulnerability Jul 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security Vulnerabilities, exploits, sensitive data

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant