Skip to content

[6.x] Fix SVG sanitization tests#14483

Merged
jasonvarga merged 2 commits into6.xfrom
svg-sanitization
Apr 13, 2026
Merged

[6.x] Fix SVG sanitization tests#14483
jasonvarga merged 2 commits into6.xfrom
svg-sanitization

Conversation

@duncanmcclean
Copy link
Copy Markdown
Member

@duncanmcclean duncanmcclean commented Apr 13, 2026

This pull request fixes failing SVG sanitization tests caused by an upstream security fix in rhukster/dom-sanitizer (GHSA-93vf-569f-22cq).

This PR fixes it by running Statamic's CSS sanitization before the DOM sanitizer, and bumping the minimum rhukster/dom-sanitizer version to ^1.0.10.

@jasonvarga jasonvarga merged commit 79f847b into 6.x Apr 13, 2026
19 checks passed
@jasonvarga jasonvarga deleted the svg-sanitization branch April 13, 2026 16:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants