basecamp / basecamp/trix

Vulnerability in DOMPurify dependency (≤ 3.3.1)

Open
#1,298 1 comment 3 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
20k
Forks
1.1k
Avg merge
3d 12h
Merged PRs (30d)
13

Description

### Vulnerability: DOMPurify ≤ 3.3.1 in dependency tree

Our dependency security checks are currently failing due to a reported vulnerability in **DOMPurify versions ≤ 3.3.1**.

**Advisory:**
https://github.com/cure53/DOMPurify/security/advisories/GHSA-cjmm-f4jc-qw8r

### Details

This package depends (directly or indirectly) on a vulnerable version of DOMPurify. This is being flagged by our security tooling and is currently causing our checks to fail.

### Impact

This issue is affecting our builds due to failing security checks.

Any updates on this would be appreciated. :)

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by tracing the dependency tree and the security tooling that reports DOMPurify, then identify the package manifest or lockfile entry bringing in version 3.3.1 or earlier. Done means the dependency resolves to a non-vulnerable DOMPurify version and the dependency security checks pass.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
build-system, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.