•  
      request #47162 Bump DOMPurify to 3.2.2
    Infos
    #47162
    Thomas Gerbet (tgerbet)
    2026-03-05 19:08
    2026-03-05 15:28
    48887
    Details
    Bump DOMPurify to 3.2.2

    https://github.com/cure53/DOMPurify/releases/tag/3.3.2

    The bypass within JSDOM does not really impact Tuleap security, JSDOM is only used within the test environments.

    Regarding the prototype pollution issue it is harder to say at the moment without a full advisory.

    Dependencies
    Empty
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Thomas Gerbet (tgerbet)
    Closed
    2026-03-05
    Attachments
    Empty
    References

    Follow-ups