Skip to content
This repository has been archived by the owner on Jun 8, 2021. It is now read-only.

Bump loofah from 2.2.0 to 2.2.1 #3

Merged
merged 1 commit into from
Mar 20, 2018

Conversation

dependabot-preview[bot]
Copy link
Contributor

Bumps loofah from 2.2.0 to 2.2.1.

Changelog

Sourced from loofah's changelog.

2.2.1 / 2018-03-19

Addresses CVE-2018-8048. Loofah allowed non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments.

This CVE's public notice is at flavorjones/loofah#144

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

If you'd like to skip this version, you can just close this PR. If you have any feedback just mention @dependabot in the comments below.

@blijblijblij blijblijblij merged commit 20df4a6 into develop Mar 20, 2018
@blijblijblij blijblijblij deleted the dependabot/bundler/develop/loofah-2.2.1 branch March 20, 2018 07:06
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants