chore(deps): update dependency linkifyjs to v4.3.2 [security]#1800
Merged
Conversation
gjulivan
previously approved these changes
Jul 30, 2025
uicontent
force-pushed
the
deps/npm-linkifyjs-vulnerability
branch
from
July 31, 2025 08:22
5bef928 to
a58782c
Compare
gjulivan
previously approved these changes
Jul 31, 2025
uicontent
force-pushed
the
deps/npm-linkifyjs-vulnerability
branch
6 times, most recently
from
August 7, 2025 08:22
571e159 to
0e785c6
Compare
uicontent
force-pushed
the
deps/npm-linkifyjs-vulnerability
branch
5 times, most recently
from
August 15, 2025 08:21
538b83d to
a3b6cd4
Compare
uicontent
force-pushed
the
deps/npm-linkifyjs-vulnerability
branch
6 times, most recently
from
August 25, 2025 08:22
e86faaa to
f1856a4
Compare
uicontent
force-pushed
the
deps/npm-linkifyjs-vulnerability
branch
5 times, most recently
from
September 1, 2025 08:21
8e79e9a to
76a677f
Compare
uicontent
force-pushed
the
deps/npm-linkifyjs-vulnerability
branch
from
September 3, 2025 08:20
76a677f to
5323025
Compare
uicontent
force-pushed
the
deps/npm-linkifyjs-vulnerability
branch
4 times, most recently
from
September 9, 2025 08:21
232c160 to
2f544b6
Compare
uicontent
force-pushed
the
deps/npm-linkifyjs-vulnerability
branch
3 times, most recently
from
September 15, 2025 08:20
1c88bbe to
3d8ef49
Compare
uicontent
force-pushed
the
deps/npm-linkifyjs-vulnerability
branch
2 times, most recently
from
September 17, 2025 08:19
24f741c to
6df28cf
Compare
uicontent
force-pushed
the
deps/npm-linkifyjs-vulnerability
branch
from
September 18, 2025 08:19
6df28cf to
a85b288
Compare
r0b1n
enabled auto-merge
September 18, 2025 12:53
r0b1n
approved these changes
Sep 18, 2025
r0b1n
disabled auto-merge
September 18, 2025 12:56
gjulivan
approved these changes
Sep 18, 2025
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.3.1->4.3.2GitHub Vulnerability Alerts
CVE-2025-8101
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Linkify (linkifyjs) allows XSS Targeting HTML Attributes and Manipulating User-Controlled Variables.This issue affects Linkify: from 4.3.1 before 4.3.2.
Release Notes
nfrasser/linkifyjs (linkifyjs)
v4.3.2Compare Source
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.