Skip to content

chore: upgrade dompurify to ^3.4.13 to address GHSA-55q2-fjhq-7xh7 - #1556

Merged
brendan-kellam merged 3 commits into
mainfrom
cursor/cve/dompurify
Aug 10, 2026
Merged

chore: upgrade dompurify to ^3.4.13 to address GHSA-55q2-fjhq-7xh7#1556
brendan-kellam merged 3 commits into
mainfrom
cursor/cve/dompurify

Conversation

@claude

@claude claude Bot commented Aug 8, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-1899

Refreshes the yarn.lock entry for dompurify from 3.4.12 to 3.4.13, which fixes GHSA-55q2-fjhq-7xh7 (IN_PLACE hook removal leaves a detached subtree executable, causing XSS).

dompurify is transitive here, reached via mermaid (^3.3.3) and posthog-js (^3.3.2). Both existing ranges already admit the patched release, so this is a lockfile refresh only. No manifest change and no resolutions override are needed.

Verification

  • yarn why dompurify reports both requesters resolving to dompurify@npm:3.4.13, with no affected version remaining in the graph.
  • yarn install completes with no further lockfile churn.
  • yarn workspace @sourcebot/web test --run: 101 files, 1191 tests passed.

🤖 Generated with Claude Code


Note

Low Risk
Lockfile-only transitive dependency patch with no application code changes; low risk aside from routine HTML sanitization behavior in mermaid/posthog-js consumers.

Overview
Security dependency bump for the transitive dompurify package: yarn.lock is refreshed from 3.4.12 to 3.4.13, addressing GHSA-55q2-fjhq-7xh7 (XSS via detached subtree after IN_PLACE hook removal). No package.json or resolutions changes—existing ranges from mermaid and posthog-js already allow the patched release.

The unreleased CHANGELOG records the upgrade under Fixed.

Reviewed by Cursor Bugbot for commit a4d6a97. Bugbot is set up for automated code reviews on this repo. Configure here.

github-actions Bot and others added 2 commits August 8, 2026 08:40
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@claude
claude Bot requested a review from brendan-kellam August 8, 2026 08:42
@github-actions

github-actions Bot commented Aug 8, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️ Status: PASS

Metric Count
Total packages 2196
Resolved (non-standard) 17
Unresolved 0
Strong copyleft 0
Weak copyleft 28

Weak Copyleft Packages (informational)

Package Version License
@img/sharp-libvips-darwin-arm64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-darwin-x64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-x64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x64 1.3.2 LGPL-3.0-or-later
@img/sharp-wasm32 0.35.3 Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm64 0.35.3 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia32 0.35.3 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x64 0.35.3 Apache-2.0 AND LGPL-3.0-or-later
axe-core 4.10.3 MPL-2.0
dompurify 3.4.13 (MPL-2.0 OR Apache-2.0)
lightningcss 1.32.0 MPL-2.0
lightningcss-android-arm64 1.32.0 MPL-2.0
lightningcss-darwin-arm64 1.32.0 MPL-2.0
lightningcss-darwin-x64 1.32.0 MPL-2.0
lightningcss-freebsd-x64 1.32.0 MPL-2.0
lightningcss-linux-arm-gnueabihf 1.32.0 MPL-2.0
lightningcss-linux-arm64-gnu 1.32.0 MPL-2.0
lightningcss-linux-arm64-musl 1.32.0 MPL-2.0
lightningcss-linux-x64-gnu 1.32.0 MPL-2.0
lightningcss-linux-x64-musl 1.32.0 MPL-2.0
lightningcss-win32-arm64-msvc 1.32.0 MPL-2.0
lightningcss-win32-x64-msvc 1.32.0 MPL-2.0
Resolved Packages (17)
Package Version Original Resolved Source
@sentry/cli 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry + GitHub repo (registry license is "FSL-1.1-MIT"; LICENSE is "Functional Source License, Version 1.1, MIT Future License". Definite license, but not an SPDX identifier and not OSI-approved)
@sentry/cli-darwin 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry + GitHub repo (registry license is "FSL-1.1-MIT"; LICENSE is "Functional Source License, Version 1.1, MIT Future License". Definite license, but not an SPDX identifier and not OSI-approved)
@sentry/cli-linux-arm 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry + GitHub repo (registry license is "FSL-1.1-MIT"; LICENSE is "Functional Source License, Version 1.1, MIT Future License". Definite license, but not an SPDX identifier and not OSI-approved)
@sentry/cli-linux-arm64 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry + GitHub repo (registry license is "FSL-1.1-MIT"; LICENSE is "Functional Source License, Version 1.1, MIT Future License". Definite license, but not an SPDX identifier and not OSI-approved)
@sentry/cli-linux-i686 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry + GitHub repo (registry license is "FSL-1.1-MIT"; LICENSE is "Functional Source License, Version 1.1, MIT Future License". Definite license, but not an SPDX identifier and not OSI-approved)
@sentry/cli-linux-x64 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry + GitHub repo (registry license is "FSL-1.1-MIT"; LICENSE is "Functional Source License, Version 1.1, MIT Future License". Definite license, but not an SPDX identifier and not OSI-approved)
@sentry/cli-win32-arm64 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry + GitHub repo (registry license is "FSL-1.1-MIT"; LICENSE is "Functional Source License, Version 1.1, MIT Future License". Definite license, but not an SPDX identifier and not OSI-approved)
@sentry/cli-win32-i686 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry + GitHub repo (registry license is "FSL-1.1-MIT"; LICENSE is "Functional Source License, Version 1.1, MIT Future License". Definite license, but not an SPDX identifier and not OSI-approved)
@sentry/cli-win32-x64 2.58.5 FSL-1.1-MIT FSL-1.1-MIT npm registry + GitHub repo (registry license is "FSL-1.1-MIT"; LICENSE is "Functional Source License, Version 1.1, MIT Future License". Definite license, but not an SPDX identifier and not OSI-approved)
codemirror-lang-elixir 4.0.0 UNKNOWN Apache-2.0 GitHub repo (npm registry has no license field; LICENSE in livebook-dev/codemirror-lang-elixir is Apache-2.0)
khroma 2.1.0 UNKNOWN MIT GitHub repo (npm registry has no license field; LICENSE in fabiospampinato/khroma is MIT)
lezer-elixir 1.1.2 UNKNOWN Apache-2.0 GitHub repo (npm registry has no license field; LICENSE in livebook-dev/lezer-elixir is Apache-2.0)
map-stream 0.1.0 UNKNOWN MIT GitHub repo (npm registry has no license field; LICENCE in dominictarr/map-stream is MIT)
memorystream 0.3.1 UNKNOWN MIT extracted from object (npm licenses: [{"type":"MIT","url":"..."}]; LICENSE text is MIT)
pause-stream 0.0.11 ["MIT","Apache2"] MIT OR Apache-2.0 extracted from object (npm license: ["MIT","Apache2"]; LICENSE states "Dual Licensed MIT and Apache 2")
posthog-js 1.369.0 SEE LICENSE IN LICENSE Apache-2.0 GitHub repo (LICENSE in PostHog/posthog-js is Apache-2.0; trailing MIT notices are third-party attributions)
valid-url 1.0.9 UNKNOWN MIT GitHub repo (npm registry has no license field; LICENSE in ogt/valid-url states "released under the MIT license")

@brendan-kellam
brendan-kellam merged commit de32661 into main Aug 10, 2026
13 checks passed
@brendan-kellam
brendan-kellam deleted the cursor/cve/dompurify branch August 10, 2026 17:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant