Skip to content

Comments

[Security] Bump loofah from 2.2.3 to 2.4.0#185

Closed
dependabot-preview[bot] wants to merge 13 commits intomasterfrom
dependabot/bundler/loofah-2.4.0
Closed

[Security] Bump loofah from 2.2.3 to 2.4.0#185
dependabot-preview[bot] wants to merge 13 commits intomasterfrom
dependabot/bundler/loofah-2.4.0

Conversation

@dependabot-preview
Copy link
Contributor

Bumps loofah from 2.2.3 to 2.4.0. This update includes a security fix.

Vulnerabilities fixed

Sourced from The Ruby Advisory Database.

Loofah XSS Vulnerability
In the Loofah gem, through v2.3.0, unsanitized JavaScript may occur in
sanitized output when a crafted SVG element is republished.

Patched versions: >= 2.3.1
Unaffected versions: none

Release notes

Sourced from loofah's releases.

2.4.0 / 2019-11-25

Features

2.3.1 / 2019-10-22

Security

Address CVE-2019-15587: Unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.

This CVE's public notice is at flavorjones/loofah#171

2.3.0 / 2019-09-28

Features

Bug fixes

  • CSS hex values are no longer limited to lowercase hex. Previously uppercase hex were scrubbed. #165 (Thanks, @​asok!)

Deprecations / Name Changes

The following method and constants are hereby deprecated, and will be completely removed in a future release:

  • Deprecate Loofah::Helpers::ActionView.white_list_sanitizer, please use Loofah::Helpers::ActionView.safe_list_sanitizer instead.
  • Deprecate Loofah::Helpers::ActionView::WhiteListSanitizer, please use Loofah::Helpers::ActionView::SafeListSanitizer instead.
  • Deprecate Loofah::HTML5::WhiteList, please use Loofah::HTML5::SafeList instead.

Thanks to @​JuanitoFatas for submitting these changes in #164 and for making the language used in Loofah more inclusive.

Changelog

Sourced from loofah's changelog.

2.4.0 / 2019-11-25

Features

2.3.1 / 2019-10-22

Security

Address CVE-2019-15587: Unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.

This CVE's public notice is at flavorjones/loofah#171

2.3.0 / 2019-09-28

Features

Bug fixes

  • CSS hex values are no longer limited to lowercase hex. Previously uppercase hex were scrubbed. #165 (Thanks, @​asok!)

Deprecations / Name Changes

The following method and constants are hereby deprecated, and will be completely removed in a future release:

  • Deprecate Loofah::Helpers::ActionView.white_list_sanitizer, please use Loofah::Helpers::ActionView.safe_list_sanitizer instead.
  • Deprecate Loofah::Helpers::ActionView::WhiteListSanitizer, please use Loofah::Helpers::ActionView::SafeListSanitizer instead.
  • Deprecate Loofah::HTML5::WhiteList, please use Loofah::HTML5::SafeList instead.

Thanks to @​JuanitoFatas for submitting these changes in #164 and for making the language used in Loofah more inclusive.

Commits
  • 724ac1c version bump to v2.4.0
  • e808fb6 ci: don't turn on frozen strings until after bundle install
  • 0eb9976 update CHANGELOG
  • 0783f5b add magic comment for frozen string literals to all files
  • 5ce3a71 add rubocop as dev dep and configure security and frozen string cops
  • 82ae384 test suite should check compatibility with frozen string literals
  • 8747065 Merge pull request #175 from bchaney/allow-css-max-width
  • 2767ae3 Merge pull request #177 from flavorjones/176-allow-rem-css-sizes
  • 13f734f css sanitizer allows "rem" sizes
  • 2699b61 Allow CSS property: max-width
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in your Dependabot dashboard:

  • Update frequency (including time of day and day of week)
  • Pull request limits (per update run and/or open at any time)
  • Automerge options (never/patch/minor, and dev/runtime dependencies)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

Duxy1996 and others added 13 commits September 4, 2019 18:34
Ignored ThreeJS loaders and helpers which are used in the 3D viewer
Bumps [nokogiri](https://github.com/sparklemotion/nokogiri) from 1.10.3 to 1.10.4. **This update includes a security fix.**
- [Release notes](https://github.com/sparklemotion/nokogiri/releases)
- [Changelog](https://github.com/sparklemotion/nokogiri/blob/master/CHANGELOG.md)
- [Commits](sparklemotion/nokogiri@v1.10.3...v1.10.4)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
* Travis - Updated Travis CI to Rails 2.4.0

* Travis - Updated Travis CI to Rails 2.4.4

* Travis - Updated Travis CI to Rails 2.5.0

* Travis - Post build scripts removed
Bumps [devise](https://github.com/plataformatec/devise) from 4.6.2 to 4.7.1.
- [Release notes](https://github.com/plataformatec/devise/releases)
- [Changelog](https://github.com/plataformatec/devise/blob/master/CHANGELOG.md)
- [Commits](heartcombo/devise@v4.6.2...v4.7.1)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
Bumps [devise-i18n](https://github.com/tigrish/devise-i18n) from 1.8.0 to 1.8.1.
- [Release notes](https://github.com/tigrish/devise-i18n/releases)
- [Changelog](https://github.com/tigrish/devise-i18n/blob/master/CHANGELOG.md)
- [Commits](tigrish/devise-i18n@v1.8.0...v1.8.1)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
Bumps [bcrypt](https://github.com/codahale/bcrypt-ruby) from `011b67b` to `2875dbf`.
- [Release notes](https://github.com/codahale/bcrypt-ruby/releases)
- [Commits](bcrypt-ruby/bcrypt-ruby@011b67b...2875dbf)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
* BADGES - Added test badge and app folder

* BADGES - Basic badges generator file. Connected with the github API using https req

* README - Readme comments tests and badges remove code

* README - AUTOGENERATED README TEST

* BADGES - Now update the contributors badge when execute the script

* BADGES - Fix new line addition bug

* BADGES - Added a new class and re-factored the scrip in several methods

* BADGES - Added several options as global variables inside the class
* Fixtures - Removed non used and bad implemented fixtures. Removed object_format which was not used in the application

* TESTS - Configured two basic tests(model and controller) and create a travis job to execute the job

* TEST - Added travis dba creation

* TRAVIS - Added postgresql 9.6 to travis file
* README - Update readme with more information,installation and history of the project

* README - Updated badges

* RESTORED-OBJECT - Removed console traces and comments
Bumps [loofah](https://github.com/flavorjones/loofah) from 2.2.3 to 2.4.0. **This update includes a security fix.**
- [Release notes](https://github.com/flavorjones/loofah/releases)
- [Changelog](https://github.com/flavorjones/loofah/blob/master/CHANGELOG.md)
- [Commits](flavorjones/loofah@v2.2.3...v2.4.0)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
@dependabot-preview dependabot-preview bot added dependencies Pull requests that update a dependency file security Pull requests that address a security vulnerability labels Nov 26, 2019
@alvarocasadoc alvarocasadoc force-pushed the master branch 2 times, most recently from e372ce0 to a2acf8d Compare January 19, 2020 17:52
@dependabot-preview
Copy link
Contributor Author

Superseded by #212.

@dependabot-preview dependabot-preview bot deleted the dependabot/bundler/loofah-2.4.0 branch April 6, 2020 05:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file security Pull requests that address a security vulnerability

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant