Skip to content

chore(deps): bump the npm_and_yarn group across 1 directory with 3 updates - #9

Merged
roll merged 1 commit into
mainfrom
dependabot/npm_and_yarn/npm_and_yarn-f58a3bd70c
Oct 6, 2026
Merged

roll merged 1 commit into
mainfrom
dependabot/npm_and_yarn/npm_and_yarn-f58a3bd70c

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the npm_and_yarn group with 3 updates in the / directory: dompurify, katex and proxy-addr.

Updates dompurify from 3.4.1 to 3.4.16

Release notes

Sourced from dompurify's releases.

DOMPurify 3.4.16

  • Fixed a problem with IN_PLACE node removal when working with hooks, thanks @​manus-pi
  • Fixed a problem with IN_PLACE sanitization and raw-text roots, thanks @​h-t-m
  • Fixed a problem with ESM default exports landing in CommonJS declarations, thanks @​ssi02014
  • Migrated from rollup to rolldown because performance, thanks @​ssi02014
  • Bumped several dependencies where possible

DOMPurify 3.4.15

  • Added better clobbering hardening when XML content is involved, thanks @​gnyselcuk
  • Added several smaller hardening and edge-case improvements, thanks @​leechristensen
  • Bumped several dependencies where possible

DOMPurify 3.4.14

  • Fixed an issue with possible bypasses when risky tags are allow-listed, thanks @​AlirezaRouhbakhsh
  • Fixed a couple of edge cases with mixed document contexts, thanks @​fishjojo1
  • Added the SVG pointer-events and vector-effect presentation attributes to the allow-list, thanks @​Jaybhade
  • Conducted another refactoring run, removed dead branches and duplicated logic, flattened attribute validation
  • Updated the documentation in several spots, README, wiki, etc., thanks @​Akokonunes
  • Updated several development dependencies and CI workflow actions

DOMPurify 3.4.13

  • Fixed an issue with hook removal during IN_PLACE sanitization, thanks @​koyokr
  • Fixed an issue with hooks potentially bypassing the clone guard, thanks @​AkshayjainG
  • Fixed an issue with DOM clobbering via ownerDocument during IN_PLACE, thanks @​AkshayjainG
  • Bumped several dependencies where possible

DOMPurify 3.4.12

  • Fixed an issue where a hook would not get called for custom elements, thanks @​Rikuxx0
  • Hardened the handling of hooks removing elements, @​mkrause-bee360
  • Added support for a few new SVG attributes, thanks @​cbn-falias & @​Develop-KIM
  • Hardened the handling of declarative partial updates
  • Updated the documentation is several spots, README, wiki, etc.
  • Bumped several dependencies where possible

DOMPurify 3.4.11

  • Fixed an issue with a leaky config for hooks via setConfig, thanks @​trace37labs
  • Bumped vulnerable development dependencies to arrive at plain 0 with npm audit
  • Updated the osv-scanner suppression list as no vulnerable dependencies are left for now
  • Updated up the linting tool-chain and removed now-redundant lint directives
  • Updated the documentation is several spots, README, wiki, etc.
  • Bumped several dependencies where possible

DOMPurify 3.4.10

  • Refactored codebase for clarity: extracted the public type declarations into types.ts
  • Decomposed the three largest sanitizer functions into focused helpers
  • Removed duplicated defaults and dead branches, consolidated SAFE_FOR_TEMPLATES scrubbing into single shared path
  • Improved per-node performance by hoisting the mXSS probe regexes and testing textContent before innerHTML
  • Added a deterministic micro-benchmark harness (npm run bench) with a --compare mode
  • Reduced CI cost by running the full three-engine browser suite once per PR
  • Refreshed the demos/ folder so every demo runs again, and added a SVG-via-<img> demo

... (truncated)

Commits

Updates katex from 0.16.45 to 0.16.47

Release notes

Sourced from katex's releases.

v0.16.47

0.16.47 (2026-05-16)

Bug Fixes

v0.16.46

0.16.46 (2026-05-13)

Bug Fixes

Changelog

Sourced from katex's changelog.

0.16.47 (2026-05-16)

Bug Fixes

0.16.46 (2026-05-13)

Bug Fixes

Commits
  • 878a61b chore(release): 0.16.47 [ci skip]
  • 7ba0027 fix: correct size of [ big delimiter (#4217)
  • 8a52ddb chore: migrate screenshotter for Safari to GitHub MacOS runner (#4206)
  • 2c25b47 chore(release): 0.16.46 [ci skip]
  • e9ee046 fix: preserve math font in some styling commands (#4214)
  • 88256c0 ci(screenshotter): require safe to test label for PRs (#4211)
  • a3fce45 ci(screenshotter): disable cache (#4209)
  • 9de4b3d chore: update linters (#4205)
  • c224153 refactor: improve typing for fonts (#4200)
  • 89a3d67 chore(deps): update dependency postcss to v8.5.10 [security] (#4202)
  • Additional commits viewable in compare view

Updates proxy-addr from 2.0.7 to 2.0.8

Release notes

Sourced from proxy-addr's releases.

2.0.8

Important

What's Changed

New Contributors

Full Changelog: jshttp/proxy-addr@v2.0.7...v2.0.8

Changelog

Sourced from proxy-addr's changelog.

2.0.8

Commits
  • a11ad82 2.0.8 (#70)
  • 780911d fix: reject IPv4 trust via mapped IPv6 subnets with a short prefix
  • 92e103e fix(ci): use publised as release trigger event (#71)
  • 3e5ac75 ci: merge coverage via artifacts, disable fail-fast, add Node.js 23-26 (#69)
  • 4b9db81 chore(ci): npm-publish via workflows (#54)
  • 655e895 build(deps-dev): bump eslint-plugin-import from 2.31.0 to 2.32.0 (#39)
  • 50ce4d0 build(deps): bump ossf/scorecard-action from 2.4.2 to 2.4.3 (#45)
  • 0fd347f build(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 (#63)
  • 6a517fa build(deps): bump github/codeql-action from 4.32.4 to 4.36.0 (#64)
  • 0d45e2a Fix "arugment" typo in README (#61)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for proxy-addr since your current version.


@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 6, 2026
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
testdocs 7cb6b27 Commit Preview URL

Branch Preview URL
Oct 06 2026, 11:05 AM

@claude

claude Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Claude finished @dependabot[bot]'s task in 20s —— View job


Review

  • Gather context (diff against origin/main)
  • Review per skills/review-changes/SKILL.md

This PR only touches pnpm-lock.yaml (dependabot grouped bump: dompurify 3.4.1→3.4.16, katex 0.16.45→0.16.47, proxy-addr 2.0.7→2.0.8). No application code changed, so there's nothing to review for correctness or this repo's own conventions — a lockfile isn't where either would surface.

The proxy-addr bump fixes CVE-2026-90711, so this is a net security improvement. No issues found — looks good to merge.

…dates

Bumps the npm_and_yarn group with 3 updates in the / directory: [dompurify](https://github.com/cure53/DOMPurify), [katex](https://github.com/KaTeX/KaTeX) and [proxy-addr](https://github.com/jshttp/proxy-addr).


Updates `dompurify` from 3.4.1 to 3.4.16
- [Release notes](https://github.com/cure53/DOMPurify/releases)
- [Commits](cure53/DOMPurify@3.4.1...3.4.16)

Updates `katex` from 0.16.45 to 0.16.47
- [Release notes](https://github.com/KaTeX/KaTeX/releases)
- [Changelog](https://github.com/KaTeX/KaTeX/blob/main/CHANGELOG.md)
- [Commits](KaTeX/KaTeX@v0.16.45...v0.16.47)

Updates `proxy-addr` from 2.0.7 to 2.0.8
- [Release notes](https://github.com/jshttp/proxy-addr/releases)
- [Changelog](https://github.com/jshttp/proxy-addr/blob/master/HISTORY.md)
- [Commits](jshttp/proxy-addr@v2.0.7...v2.0.8)

---
updated-dependencies:
- dependency-name: dompurify
  dependency-version: 3.4.16
  dependency-type: indirect
- dependency-name: katex
  dependency-version: 0.16.47
  dependency-type: indirect
- dependency-name: proxy-addr
  dependency-version: 2.0.8
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/npm_and_yarn-f58a3bd70c branch from 1b19825 to 7cb6b27 Compare October 6, 2026 11:04
@claude

claude Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Claude finished @dependabot[bot]'s task in 50s —— View job


Claude finished reviewing @dependabot[bot]'s PR — using the review-changes skill


Review

  • Gather context (git diff origin/main...HEAD)
  • Review per skills/review-changes/SKILL.md

Diff is still lockfile-only: pnpm-lock.yaml +13/-21, same content as the previous review (dependabot grouped bump: dompurify 3.4.1→3.4.16, katex 0.16.45→0.16.47, proxy-addr 2.0.7→2.0.8, plus the transitive @jridgewell/sourcemap-codec 1.5.5→1.6.0 bump it pulls in). No application code changed, so there's nothing to assess against correctness, security-in-app-code, or this repo's conventions — none of those surface in a lockfile diff.

The proxy-addr bump fixes CVE-2026-90711, so this is a net security improvement with no downside observed. No issues found — looks good to merge.

@roll
roll merged commit 682ff7f into main Oct 6, 2026
7 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/npm_and_yarn-f58a3bd70c branch October 6, 2026 11:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant