•  
      request #13009 Update DOMPurify to 1.0.10 due to security issues
    Infos
    #13009
    Thomas Gerbet (tgerbet)
    2019-02-20 14:10
    2019-02-20 08:43
    13877
    Details
    Update DOMPurify to 1.0.10 due to security issues
    DOMPurify 1.0.10 has been released with some security fixes. The usage of the library in the Tuleap codebase are currently not impacted by the security issues.

    Tuleap uses DOMPurify 1.0.9 and 1.0.8, the 1.0.9 also comes with nice improvements like a squashed memory leak and support for trusted types.


    Release note:
    https://github.com/cure53/DOMPurify/releases/tag/1.0.10
    https://github.com/cure53/DOMPurify/releases/tag/1.0.9
    Other
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Empty
    Closed
    2019-02-20
    Attachments
    Empty
    References

    Follow-ups