Vulnerability in DOMPurify dependency (≤ 3.3.1)
- Dominant language
- JavaScript
- Stars
- 20k
- Forks
- 1.1k
- Avg merge
- 3d 12h
- Merged PRs (30d)
- 13
Description
### Vulnerability: DOMPurify ≤ 3.3.1 in dependency tree
Our dependency security checks are currently failing due to a reported vulnerability in **DOMPurify versions ≤ 3.3.1**.
**Advisory:**
https://github.com/cure53/DOMPurify/security/advisories/GHSA-cjmm-f4jc-qw8r
### Details
This package depends (directly or indirectly) on a vulnerable version of DOMPurify. This is being flagged by our security tooling and is currently causing our checks to fail.
### Impact
This issue is affecting our builds due to failing security checks.
Any updates on this would be appreciated. :)
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by tracing the dependency tree and the security tooling that reports DOMPurify, then identify the package manifest or lockfile entry bringing in version 3.3.1 or earlier. Done means the dependency resolves to a non-vulnerable DOMPurify version and the dependency security checks pass.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- build-system, security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 48/100