fix(deps): update dependency @xmldom/xmldom to ^0.8.0 #7
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^0.7.5
->^0.8.0
Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
xmldom/xmldom (@xmldom/xmldom)
v0.8.10
Compare Source
Fixed
#514
/#499
Thank you, @qtow, for your contributions
v0.8.9
Compare Source
Fixed
#509
/#505
Thank you, @cjbarth, for your contributions
v0.8.8
Compare Source
Fixed
#489
Thank you, @zorkow, for your contributions
v0.8.7
Compare Source
Fixed
#485
/#486
Thank you, @bulandent, for your contributions
v0.8.6
Compare Source
Fixed
#457
/#455
/#456
Thank you, @edemaine, @pedro-l9, for your contributions
v0.8.5
Compare Source
Fixed
#452
/#453
Thank you, @fengxinming, for your contributions
v0.8.4
Compare Source
Fixed
CVE-2022-39353
In case such a DOM would be created, the part that is not well-formed will be transformed into text nodes, in which xml specific characters like
<
and>
are encoded accordingly.In the upcoming version 0.9.0 those text nodes will no longer be added and an error will be thrown instead.
This change can break your code, if you relied on this behavior, e.g. multiple root elements in the past. We consider it more important to align with the specs that we want to be aligned with, considering the potential security issues that might derive from people not being aware of the difference in behavior.
Related Spec: https://dom.spec.whatwg.org/#concept-node-ensure-pre-insertion-validity
Thank you, @frumioj, @cjbarth, @markgollnick for your contributions
v0.8.3
Compare Source
Fixed
#437
/#436
Thank you, @Supraja9726 for your contributions
v0.8.2
Compare Source
Fixed
>
as specified (#395)#58
Other
nodeType
values to public interface description#396
#317
>
as specified#395
Object.assign
ponyfill#379
#378
Thank you @niklasl, @cburatto, @SheetJSDev, @pyrsmk for your contributions
v0.8.1
Compare Source
Fixed
#514
/#499
Thank you, @qtow, for your contributions
v0.8.0
Compare Source
Fixed
BREAKING CHANGE: Certain combination of line break characters are normalized to a single
\n
before parsing takes place and will no longer be preserved.#303
/#307
#49
,#97
,#324
/#314
#284
/#310
BREAKING CHANGE: If you relied on the not spec compliant preservation of literal
\t
,\n
or\r
in attribute values.To preserve those you will have to create XML that instead contains the correct numerical (or hexadecimal) equivalent (e.g.
	
,

,
).DOMImplementation
andXMLSerializer
fromlib/dom-parser.js
#53 /#309
BREAKING CHANGE: Use the one provided by the main package export.
removeChild
#343
/#355
Chore
#325
#111
/#304
Thank you @marrus-sh, @victorandree, @mdierolf, @tsabbay, @fatihpense for your contributions
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate. View repository job log here.