Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Replace xmldom with @xmldom/xmldom to fix critical vulnerability #1710

Open
1 task done
sbourouis opened this issue Aug 31, 2023 · 1 comment
Open
1 task done

Replace xmldom with @xmldom/xmldom to fix critical vulnerability #1710

sbourouis opened this issue Aug 31, 2023 · 1 comment

Comments

@sbourouis
Copy link

sbourouis commented Aug 31, 2023

Would you like to work on this feature?

  • Check this if you would like to implement a PR, we are more than happy to help you go through the process.

What problem are you trying to solve?

There is a critical vulnerability in the xmldom package (See GHSA-crh6-fp67-6883)
And the xmldom package won't be updated (see xmldom/xmldom#271), only @xmldom/xmldom is maintained so for future security patches, it would also be better to use @xmldom/xmldom

Describe the solution you'd like

Update to @xmldom/xmldom@~0.7.7, @xmldom/xmldom@~0.8.4 (dist-tag latest) or @xmldom/xmldom@>=0.9.0-beta.4 (dist-tag next).
A PR is currently opened here #1698 but it seems like no one took a look at it and a lot of tests are failing. I have completed the changes in #1711

Describe alternatives you've considered

No response

Documentation, Adoption, Migration Strategy

No response

@sbourouis
Copy link
Author

I have completed the changes in #1711

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant