Update dependency prismjs to v1.25.0 [SECURITY] #148
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.15.0->1.25.0GitHub Vulnerability Alerts
CVE-2020-15138
Impact
The easing preview of the Previewers plugin has an XSS vulnerability that allows attackers to execute arbitrary code in Safari and Internet Explorer.
This impacts all Safari and Internet Explorer users of Prism >=v1.1.0 that use the Previewers plugin (>=v1.10.0) or the Previewer: Easing plugin (v1.1.0 to v1.9.0).
Patches
This problem is patched in v1.21.0.
Workarounds
To workaround the issue without upgrading, disable the easing preview on all impacted code blocks. You need Prism v1.10.0 or newer to apply this workaround.
References
The vulnerability was introduced by this commit on Sep 29, 2015 and fixed by Masato Kinugawa (#2506).
For more information
If you have any questions or comments about this advisory, please open an issue.
CVE-2021-23341
The package prismjs before 1.23.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the
prism-asciidoc,prism-rest,prism-tapandprism-eiffelcomponents.CVE-2021-32723
Some languages before 1.24.0 are vulnerable to Regular Expression Denial of Service (ReDoS).
Impact
When Prism is used to highlight untrusted (user-given) text, an attacker can craft a string that will take a very very long time to highlight. Do not use the following languages to highlight untrusted text.
Other languages are not affected and can be used to highlight untrusted text.
Patches
This problem has been fixed in Prism v1.24.
References
CVE-2021-3801
Prism is a syntax highlighting library. The prismjs package is vulnerable to ReDoS (regular expression denial of service). An attacker that is able to provide a crafted HTML comment as input may cause an application to consume an excessive amount of CPU.
Release Notes
PrismJS/prism (prismjs)
v1.25.0Compare Source
New components
746a4b1a87e5a376c1dce99823cd9b654f97b82bea776756e008ea05a1b67ce34fbdd2f8148c1eca4433ccfc8df825e06a356d25Updated components
748bb9acwithkeyword & improved record support (#2993)fdd291c0record,init, andnullablekeyword (#2991)9b561565fromkeyword (#2970)158f25d45de8947f8d0b74b59c8911bd693b7433emptykeyword (#2997)fe3bc526b0365e7052e8cee90ff371bb∀a keyword (alias forforall) (#3005)b38fc89a679539ec6f5d68f714fdfe3235b88fcf4492b62b8541db2e@propertyWrapper,@MainActor, and@globalActor(#3009)ce5e0f01bb93fac0212e0ef2Updated plugins
5126d1e1e289ec6063edf14cc7b6a7f6Updated themes
ffb20439Other
44456b21e997dd35d216e602247fd9a3v1.24.1Compare Source
Updated components
151121cdUpdated plugins
748ecddcv1.24.0Compare Source
New components
b0a6ec853f7d74537e5f78ff41e25d3cf9b695281f91868e99a21dc5bf4e7ba9e93144157e51b99c3419fb772bc6475bf84c49c51a2347a318c67b491b63cd01e38986f9fd1081d2bbc77d1972962701c4f6b2ccUpdated components
regexp/no-dupe-disjunctions(#2952)f471d2d779d22182d85e30daea82478dfc2a3334e4ad22ade5cfdb4a::punctuation (#2814)3df62fd088fa72cfd0bcd07493dd83c2114e4626e6c0d298defdelagatekeyword and highlighting for function/module names (#2709)59f725d7a5d7178cdefinition-queryanddefinition-mutationtokens (#2964)bfd7fded34f24ac9hbsalias (#2874)439763511dfc82716183fd9b4e7b2a8242d24fa24ec7535cab7c9953415651a09c610ae6022f90a0abab9104cf28d1b2ac1d12f945ec4a88e9477d83wraphook (#2719)2b355c988dbbbb355943f4cb87d79390cf3755cbfnkeyword (#2858)e0ee93f17e8cd40d8019e2f6f79b0eef04ef309c01af04ed9f59f52d30b0444finlinepattern (#2946)a7656de620b77bff3786f396f08c2f7f0e61a7e11c6c0bf3cda976b1c83fd0b8ILIKEoperator (#2704)6e34771fsomekeyword (#2756)cf354ef5fe98d53631cc2142a68f1fb6REMis no longer highlighted as a keyword in comments (#2823)ebbbfd47e32e043b459365ecUpdated plugins
4b55bd6a96335642c81c3319d5e14e1aclipboard.writeTextnot working inside iFrames (#2826)01b7b6f74d7f75b02cb909e153d34b22ccc73ab7classListinstead ofclassName(#2787)d298d46eOther
tabindexto code blocks to enable keyboard navigation (#2799)dbf70515b37987d3970674cfnpm-run-allto clean up test command (#2938)5d3d80887cd9e794b77317c545b0e82a0feb266fad9878ad--languagefor patterns tests (#2929)a62ef7968dbf1217a9a199b64492c5ce531514045bc405e799f3ddcd--insertand--updateparameters to language test (#2809)4c8b855dcomponents.jsontests (#2758)933af8057a790bf9npm ci(#2899)91f3aaedcb220168266cc700my.cdnin code sample with Handlebars-like placeholder (#2906)8047118138f1d2899b784ebfa1209930ec9767d61506f345v1.23.0Compare Source
New components
f0e2b70e0803525b8831c706Updated components
c2f6a644=(#2612)00bf00e30a3932fe129faf5cf1541342a7ccc16dstyleattribute tokenization (#2569)b04cbafe0889bc7c73f81c890bb4f096093c8175a5107d5c89f1e1822af3e2c25cf9cfbc38808e64df922d9089ebb0b737b9c9a1deb238a6e01ecd007951ca248e76a97825bdb494Updated plugins
7a74497atype="button"attribute for copy to clipboard plugin (#2593)f59a85f13f4ae00db40f8f4bcdb24abe7cdfe5567266e32ffc602822Other
071232b42ea202b9f217ab75245744068fa8dd24691320459df20c5estartscript to start local server (#2491)0604793c05afbb10e644178b8bfcc8192d3a12670df60be1Prism.languages.extend(#2572)8828500eb5f4f10edf0738e99f82de50add3736a8e6604958e1f38ffv1.22.0Compare Source
New components
4d31e22a5c33f0bb004eaa74388ad996ad748a00cb75d9e22da2bebabf115f47Updated components
fa2225ffe023044cc51ababbbcef22afmatchkeyword (PHP 8.0) (#2574)1761513e35cbc02ff62ca7873b4f14cae4f6ccacbfb367486c92180159853a52Updated plugins
d36ea9936b47133da409245eOther
bafab634206dc80fbf169e5f655f985c8ae6a4ba5ad6cb23v1.21.0Compare Source
New components
3fcce6fe3a127c7dde21eb64398e2943649e51e5ed8fff9187a5c7aeae0327b3bd4d8165d0c1c70d053016ef22eb5cad8704cdfb1093ceb3cde5b0facaec5e30ed1df1e1Updated components
9782cfe67a554b5f⍥(#2409)0255cb6aformatbuilt-in (#2450)7c66cfc4ddf3cc624fe03676composercommand (#2298)044dd271f0f8210c8a72fa6ffdcf7ed27f341fc12a2e79ed8e9d161ce3fe9040enum classclass names (#2342)30b4e254537a9e80964de5a1classandidpatterns ([#&Redesign again #8Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.