Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(deps): update dependency prismjs to v1.23.0 [security] #388

Merged
merged 1 commit into from
May 14, 2021

Conversation

renovate[bot]
Copy link

@renovate renovate bot commented Aug 7, 2020

WhiteSource Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
prismjs 1.20.0 -> 1.23.0 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2020-15138

Impact

The easing preview of the Previewers plugin has an XSS vulnerability that allows attackers to execute arbitrary code in Safari and Internet Explorer.

This impacts all Safari and Internet Explorer users of Prism >=v1.1.0 that use the Previewers plugin (>=v1.10.0) or the Previewer: Easing plugin (v1.1.0 to v1.9.0).

Patches

This problem is patched in v1.21.0.

Workarounds

To workaround the issue without upgrading, disable the easing preview on all impacted code blocks. You need Prism v1.10.0 or newer to apply this workaround.

References

The vulnerability was introduced by this commit on Sep 29, 2015 and fixed by Masato Kinugawa (#​2506).

For more information

If you have any questions or comments about this advisory, please open an issue.

CVE-2021-23341

The package prismjs before 1.23.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the prism-asciidoc, prism-rest, prism-tap and prism-eiffel components.


Release Notes

PrismJS/prism

v1.23.0

Compare Source

New components
Updated components
Updated plugins
Other

v1.22.0

Compare Source

New components
Updated components
Updated plugins
Other

v1.21.0

Compare Source

New components
Updated components
Updated plugins
Updated themes
  • Coy
  • Default
    • Added a comment that declares the background color of operator tokens as intentional (#​2309) 937e2691
  • Okaidia
    • Update comment text color to meet WCAG contrast recommendations to AA level (#​2292) 06495f90
Other

Configuration

📅 Schedule: "" (UTC).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻️ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box.

This PR has been generated by WhiteSource Renovate. View repository job log here.

@renovate renovate bot added the renovate label Aug 7, 2020
@renovate renovate bot force-pushed the renovate/npm-prismjs-vulnerability branch 7 times, most recently from 7568b5a to 0863579 Compare August 14, 2020 14:05
@renovate renovate bot force-pushed the renovate/npm-prismjs-vulnerability branch from 0863579 to 66655e9 Compare October 10, 2020 18:52
@renovate renovate bot force-pushed the renovate/npm-prismjs-vulnerability branch 2 times, most recently from c4b46e1 to 586a9d6 Compare October 28, 2020 08:48
@renovate renovate bot force-pushed the renovate/npm-prismjs-vulnerability branch from 586a9d6 to 921bf00 Compare November 28, 2020 10:54
@renovate renovate bot force-pushed the renovate/npm-prismjs-vulnerability branch from 921bf00 to 2d3aaf0 Compare January 6, 2021 21:58
@renovate renovate bot force-pushed the renovate/npm-prismjs-vulnerability branch from 2d3aaf0 to dbe7f80 Compare January 24, 2021 11:55
@renovate renovate bot force-pushed the renovate/npm-prismjs-vulnerability branch from dbe7f80 to cc57b6f Compare February 22, 2021 13:21
@renovate renovate bot changed the title fix(deps): update dependency prismjs to v1.21.0 [security] fix(deps): update dependency prismjs to ^1.21.0 [security] Feb 22, 2021
@renovate renovate bot force-pushed the renovate/npm-prismjs-vulnerability branch from cc57b6f to 21e8af4 Compare February 25, 2021 13:25
@renovate renovate bot changed the title fix(deps): update dependency prismjs to ^1.21.0 [security] fix(deps): update dependency prismjs to v1.21.0 [security] Feb 25, 2021
@renovate renovate bot changed the title fix(deps): update dependency prismjs to v1.21.0 [security] fix(deps): update dependency prismjs to v1.23.0 [security] Mar 1, 2021
@renovate renovate bot force-pushed the renovate/npm-prismjs-vulnerability branch 2 times, most recently from a8a3f44 to 0e48893 Compare March 10, 2021 22:24
@renovate renovate bot force-pushed the renovate/npm-prismjs-vulnerability branch from 0e48893 to 1b31913 Compare May 9, 2021 21:41
@vstoms vstoms merged commit c5bc530 into master May 14, 2021
@renovate renovate bot deleted the renovate/npm-prismjs-vulnerability branch May 14, 2021 10:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants