Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We鈥檒l occasionally send you account related emails.

Already on GitHub? Sign in to your account

Removal of vulnerability #2958

Merged
merged 1 commit into from Apr 21, 2022
Merged

Removal of vulnerability #2958

merged 1 commit into from Apr 21, 2022

Conversation

knsv
Copy link
Collaborator

@knsv knsv commented Apr 21, 2022

馃搼 Summary

Brief description about the content of your PR.

Resolves #2957

馃搹 Design Decisions

Describe the way your implementation works or what design decisions you made if applicable.

馃搵 Tasks

Make sure you

  • 馃摉 have read the contribution guidelines
  • 馃捇 have added unit/e2e tests (if appropriate)
  • 馃敄 targeted develop branch

@knsv knsv merged commit c0bdf9d into develop Apr 21, 2022
LeSuisse added a commit to Enalean/tuleap that referenced this pull request May 5, 2022
)

Changes:
https://github.com/mermaid-js/mermaid/releases/tag/9.0.0
https://github.com/mermaid-js/mermaid/releases/tag/9.0.1

This includes a fix for a sanitizing library Mermaid uses (CVE-2021-23648 [0])
and a direct fix for a Mermaid security issue [1].

[0] GHSA-hqq7-2q2v-82xq
[1] mermaid-js/mermaid#2958

Change-Id: Ifedba57d22797ae90b4d60f1238ae530bda7b86b
@knsv knsv deleted the decode_entities_update branch August 23, 2022 17:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Removal of vulnerability that be used to add XSS to links
1 participant