Skip to content

[WC-3540]: chore(html-element-web): bump dompurify to 3.4.13 - #2376

Merged
r0b1n merged 1 commit into
mainfrom
chore/html-element-dompurify-3.4.13
Aug 10, 2026
Merged

[WC-3540]: chore(html-element-web): bump dompurify to 3.4.13#2376
r0b1n merged 1 commit into
mainfrom
chore/html-element-dompurify-3.4.13

Conversation

@r0b1n

@r0b1n r0b1n commented Aug 10, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • Bumped dompurify from 3.4.12 to 3.4.13 in html-element-web
  • Updated pnpm-lock.yaml (only dompurify changed)
  • Added changelog entry under [Unreleased]

Test plan

  • Verify widget builds successfully
  • Confirm no regressions in HTML sanitization behavior

@r0b1n
r0b1n requested a review from a team as a code owner August 10, 2026 08:18
@github-actions

Copy link
Copy Markdown
Contributor

AI Code Review

✅ Approved — no issues found


What was reviewed

File Change
packages/pluggableWidgets/html-element-web/CHANGELOG.md Added ### Security entry under [Unreleased] for dompurify bump
packages/pluggableWidgets/html-element-web/package.json Bumped dompurify dependency from ^3.4.12^3.4.13

Skipped (out of scope): pnpm-lock.yaml


Positives

  • Changelog entry is correctly categorized under ### Security (Keep a Changelog format) — matches the nature of the change.
  • Changelog message is user-facing and benefit-oriented ("incorporate latest security fixes"), not an implementation detail.
  • Lockfile updated in the same PR, ensuring deterministic builds.
  • Change is tightly scoped to only the affected package — no collateral edits.

@r0b1n
r0b1n merged commit d42c418 into main Aug 10, 2026
14 of 15 checks passed
@r0b1n
r0b1n deleted the chore/html-element-dompurify-3.4.13 branch August 10, 2026 08:25
@r0b1n r0b1n changed the title chore(html-element-web): bump dompurify to 3.4.13 [WC-3540]: chore(html-element-web): bump dompurify to 3.4.13 Aug 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants