[5.3] Security updates for composer and npm dependencies for the upcoming 5.3.4 release#45984
Merged
HLeithner merged 2 commits intojoomla:5.3-devfrom Aug 27, 2025
Merged
Conversation
Member
|
thanks |
softforge
pushed a commit
that referenced
this pull request
Aug 28, 2025
* [5.3] Translation Update (#45983) * Fix copy / paste error (#45979) * [5.3] Security updates for composer and npm dependencies for the upcoming 5.3.4 release (#45984) * composer update enshrined/svg-sanitize to 0.22.0 * npm fix audit issues * [5.3] Update TinyMCE from 6.8.5 to 6.8.6 to fix TinyMCE issue with cursor placement (#45987) * npm update tinymce from 6.8.5 to 6.8.6 * Update version in tinymce.xml * [5.4] Revert b/c breaking change in AbstractView::get (#45940) * Revert "[5.4] Replace deprecation AbstractView::get() in layouts (#45702)" * This reverts commit f1906ba. * [5.3] Update joomla/filesystem to fix extension uploads when post_max_size is 0 (#45986) * [5.4] Upmerge 2025-08-28 (#45997) * [5.3] Translation Update #45983 * [5.3] Fix copy / paste error in form fields #45979 * [5.3] Security updates for composer and npm dependencies for the upcoming 5.3.4 release #45984 * [5.3] Update joomla/filesystem to fix extension uploads when post_max_size is 0 #45986 * [5.4] Composer update joomla/filesystem to 3.2.0 (#45999) * Update content-hash
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Pull Request for Issue # .
Summary of Changes
This pull request (PR) updates composer and npm dependencies to fix security issues reported by
composer auditandnpm audit.Details see https://github.com/darylldoyle/svg-sanitizer/releases/tag/0.22.0
Details see https://github.com/juliangruber/brace-expansion/releases/tag/v1.1.12
and https://github.com/juliangruber/brace-expansion/releases/tag/v2.0.2
Details see https://github.com/form-data/form-data/releases/tag/v4.0.3
and https://github.com/form-data/form-data/releases/tag/v4.0.4
Details see https://github.com/raszi/node-tmp/releases/tag/v0.2.4
and https://github.com/raszi/node-tmp/releases/tag/v0.2.5
Testing Instructions
It needs a development environment (git clone + composer + npm) for testing.
For the actual result use the 5.3-dev branch of this repository (or of your clone if that is up to date with the upstream).
For the expected result you can fetch this PR into a local branch with a name of your choice, here as example "":
composer install.npm ci.composer audit.npm audit.Actual result BEFORE applying this Pull Request
composer audit:npm audit:Expected result AFTER applying this Pull Request
composer audit:npm audit:Additional information
In the 5.4-dev and the 6.0-dev branches, only the composer dependency "enshrined/svg-sanitize" and the npm dependency "tmp" need to be updated like here, all other dependencies handled in this PR here are already up to date in the mentioned branches. This will be handled with the upmerges by the release managers.
Link to documentations
Please select:
Documentation link for docs.joomla.org:
No documentation changes for docs.joomla.org needed
Pull Request link for manual.joomla.org:
No documentation changes for manual.joomla.org needed