•  
      request #47557 Temporarily ignore GHSA-h8r8-wccr-v5f2
    Infos
    #47557
    Joris MASSON (jmasson)
    2026-03-31 16:05
    2026-03-31 10:37
    49282
    Details
    Temporarily ignore GHSA-h8r8-wccr-v5f2

    See Advisory: https://github.com/advisories/GHSA-h8r8-wccr-v5f2

    It's an issue affecting DOMPurify versions before 3.3.2. All uses in Tuleap production code are set to version 3.3.2 (since request #47162), except for one use in slides for documentation. Tuleap itself is not affected by this issue.

    For the remaining use in slides, the version cannot be upgraded, as DOMPurify is bundled within monaco-editor, so we choose to temporarily ignore it.

    Dev tools
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Joris MASSON (jmasson)
    Closed
    2026-03-31
    Attachments
    Empty
    References
    Referenced by request #47557

    Follow-ups

    User avatar
    Joris MASSON (jmasson)2026-03-31 10:42
    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes