Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update module github.com/microcosm-cc/bluemonday to v1.0.27 #34

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link

@renovate renovate bot commented Jan 28, 2023

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
github.com/microcosm-cc/bluemonday v1.0.21 -> v1.0.27 age adoption passing confidence

Release Notes

microcosm-cc/bluemonday (github.com/microcosm-cc/bluemonday)

v1.0.27

Compare Source

v1.0.26: Update golang.org/x/net to latest and force latest version

Compare Source

Bumping version and ensuring latest golang.org/x/net as the HTTP rapid reset is triggering primitive vuln scanners, we do not implement a HTTP2 server and are not vulnerable but a minor bump can still help reduce noise for those searching for what they need to upgrade and patch.

Nothing else is in this release aside from the dependency updates and some staticcheck messages being resolved that should not modify behaviour.

v1.0.25: Added src rewriter to allow for proxying inline assets.

Compare Source

What's Changed

New Contributors

Full Changelog: microcosm-cc/bluemonday@v1.0.24...v1.0.25

v1.0.24: Added AllowURLSchemesMatching

Compare Source

This is a feature release, there are no security fixes in this release.

What's Changed

New Contributors

Full Changelog: microcosm-cc/bluemonday@v1.0.23...v1.0.24

v1.0.23: Resolve golang.org/x/net CVE-2022-41723

Compare Source

What's Changed

New Contributors

Full Changelog: microcosm-cc/bluemonday@v1.0.22...v1.0.23

v1.0.22: Add picture to list of elements allowed without attributes

Compare Source

This is not a security update!

This is a usability update as some HTML elements are valid without attributes however the default behaviour is to strip these out of an abundance of caution. The picture element https://developer.mozilla.org/en-US/docs/Web/HTML/Element/picture is one such element where it merely changes the browser rendering such that one of the child elements will be rendered.

The picture element was not present in the allowlist when it should have been, and so this release fixes that as per #​161 .


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the renovate Automated action from Renovate label Jan 28, 2023
@renovate renovate bot changed the title Update module github.com/microcosm-cc/bluemonday to v1.0.22 Update module github.com/microcosm-cc/bluemonday to v1.0.23 Mar 7, 2023
@renovate renovate bot force-pushed the renovate/github.com-microcosm-cc-bluemonday-1.x branch from c10b6de to bd86b8f Compare March 7, 2023 12:32
@renovate renovate bot changed the title Update module github.com/microcosm-cc/bluemonday to v1.0.23 Update module github.com/microcosm-cc/bluemonday to v1.0.24 May 29, 2023
@renovate renovate bot force-pushed the renovate/github.com-microcosm-cc-bluemonday-1.x branch from bd86b8f to cde7c87 Compare May 29, 2023 23:43
@renovate renovate bot changed the title Update module github.com/microcosm-cc/bluemonday to v1.0.24 Update module github.com/microcosm-cc/bluemonday to v1.0.25 Jul 19, 2023
@renovate renovate bot force-pushed the renovate/github.com-microcosm-cc-bluemonday-1.x branch from cde7c87 to c778d48 Compare July 19, 2023 05:17
@renovate renovate bot changed the title Update module github.com/microcosm-cc/bluemonday to v1.0.25 Update module github.com/microcosm-cc/bluemonday to v1.0.26 Oct 13, 2023
@renovate renovate bot force-pushed the renovate/github.com-microcosm-cc-bluemonday-1.x branch from c778d48 to 42be8e1 Compare October 13, 2023 05:26
@renovate renovate bot force-pushed the renovate/github.com-microcosm-cc-bluemonday-1.x branch from 42be8e1 to 038b86e Compare November 17, 2023 08:39
@renovate renovate bot force-pushed the renovate/github.com-microcosm-cc-bluemonday-1.x branch from 038b86e to ace2e65 Compare January 29, 2024 20:54
@renovate renovate bot force-pushed the renovate/github.com-microcosm-cc-bluemonday-1.x branch from ace2e65 to 35d6384 Compare February 26, 2024 02:52
@renovate renovate bot force-pushed the renovate/github.com-microcosm-cc-bluemonday-1.x branch from 35d6384 to fd488fb Compare April 14, 2024 08:48
@renovate renovate bot force-pushed the renovate/github.com-microcosm-cc-bluemonday-1.x branch from fd488fb to 7999c04 Compare May 9, 2024 08:58
Copy link
Author

renovate bot commented Jun 4, 2024

ℹ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 4 additional dependencies were updated

Details:

Package Change
github.com/gorilla/css v1.0.0 -> v1.0.1
golang.org/x/crypto v0.4.0 -> v0.24.0
golang.org/x/net v0.4.0 -> v0.26.0
golang.org/x/sys v0.3.0 -> v0.21.0

@renovate renovate bot force-pushed the renovate/github.com-microcosm-cc-bluemonday-1.x branch from 7999c04 to f513b69 Compare June 4, 2024 20:39
@renovate renovate bot force-pushed the renovate/github.com-microcosm-cc-bluemonday-1.x branch from f513b69 to 368d3a6 Compare July 4, 2024 20:27
@renovate renovate bot changed the title Update module github.com/microcosm-cc/bluemonday to v1.0.26 Update module github.com/microcosm-cc/bluemonday to v1.0.27 Jul 4, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
renovate Automated action from Renovate
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants