Skip to content

Conversation

domcleal
Copy link
Contributor

Summary

Switches to the newer DOMPurify 3.x branch with fix for CVE-2025-26791, as reported by GitHub on repos using Decap and decap-cms-widget-markdown.

The 3.x branch drops MSIE support, which isn't needed in Decap per #674.

Test plan

Verified decap-cms-widget-markdown/src/__tests__/renderer.spec.js is still passing.

Checklist

Please add a x inside each checkbox:

Switch to 3.x branch with fix for CVE-2025-26791. The 3.x branch drops
MSIE support, which isn't needed in Decap.
@domcleal domcleal requested a review from a team as a code owner July 11, 2025 10:33
@domcleal domcleal changed the title chore: update dompurify chore(markdown): update dompurify Jul 11, 2025
@demshy demshy merged commit 8ce98f9 into decaporg:main Jul 11, 2025
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants