Commit 580db0b
chore: upgrade dompurify to ^3.4.9 to address CVE-2026-49978
Refresh the dompurify lockfile entry (transitive via posthog-js, range
^3.3.2) from 3.4.0 to 3.4.11, which covers CVE-2026-49978 (IN_PLACE
sanitization bypass via shadow root inside <template>.content).
Generated with [Linear](https://linear.app/sourcebot/issue/SOU-1348/sourcebot-devsourcebot-cve-2026-49978-dompurify-in-place-sanitization#agent-session-a400c836)
Co-authored-by: linear-code[bot] <222613912+linear-code[bot]@users.noreply.github.com>1 parent e626691 commit 580db0b
2 files changed
Lines changed: 4 additions & 3 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
10 | 10 | | |
11 | 11 | | |
12 | 12 | | |
| 13 | + | |
13 | 14 | | |
14 | 15 | | |
15 | 16 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
13127 | 13127 | | |
13128 | 13128 | | |
13129 | 13129 | | |
13130 | | - | |
13131 | | - | |
| 13130 | + | |
| 13131 | + | |
13132 | 13132 | | |
13133 | 13133 | | |
13134 | 13134 | | |
13135 | 13135 | | |
13136 | 13136 | | |
13137 | | - | |
| 13137 | + | |
13138 | 13138 | | |
13139 | 13139 | | |
13140 | 13140 | | |
| |||
0 commit comments