Update dependency prismjs to v1.30.0 [SECURITY] #110
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.15.0->1.30.0GitHub Vulnerability Alerts
CVE-2020-15138
Impact
The easing preview of the Previewers plugin has an XSS vulnerability that allows attackers to execute arbitrary code in Safari and Internet Explorer.
This impacts all Safari and Internet Explorer users of Prism >=v1.1.0 that use the Previewers plugin (>=v1.10.0) or the Previewer: Easing plugin (v1.1.0 to v1.9.0).
Patches
This problem is patched in v1.21.0.
Workarounds
To workaround the issue without upgrading, disable the easing preview on all impacted code blocks. You need Prism v1.10.0 or newer to apply this workaround.
References
The vulnerability was introduced by this commit on Sep 29, 2015 and fixed by Masato Kinugawa (#2506).
For more information
If you have any questions or comments about this advisory, please open an issue.
CVE-2021-23341
The package prismjs before 1.23.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the
prism-asciidoc,prism-rest,prism-tapandprism-eiffelcomponents.CVE-2021-32723
Some languages before 1.24.0 are vulnerable to Regular Expression Denial of Service (ReDoS).
Impact
When Prism is used to highlight untrusted (user-given) text, an attacker can craft a string that will take a very very long time to highlight. Do not use the following languages to highlight untrusted text.
Other languages are not affected and can be used to highlight untrusted text.
Patches
This problem has been fixed in Prism v1.24.
References
CVE-2021-3801
Prism is a syntax highlighting library. The prismjs package is vulnerable to ReDoS (regular expression denial of service). An attacker that is able to provide a crafted HTML comment as input may cause an application to consume an excessive amount of CPU.
CVE-2022-23647
Impact
Prism's Command line plugin can be used by attackers to achieve an XSS attack. The Command line plugin did not properly escape its output, leading to the input text being inserted into the DOM as HTML code.
Server-side usage of Prism is not impacted. Websites that do not use the Command Line plugin are also not impacted.
Patches
This bug has been fixed in v1.27.0.
Workarounds
Do not use the Command line plugin on untrusted inputs, or sanitized all code blocks (remove all HTML code text) from all code blocks that use the Command line plugin.
References
CVE-2024-53382
Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.
Release Notes
PrismJS/prism (prismjs)
v1.30.0Compare Source
What's Changed
currentScriptis set by a script tag by @lkuechler in #3863New Contributors
Full Changelog: PrismJS/prism@v1.29.0...v1.30.0
v1.29.0Compare Source
New components
1134bdfc859f99a0c8462a29321198232815f6994c87d418Updated components
c4cbeeaa6b824d47javaandsysctlcommands. (#3505)b9512b22cargocommand (#3488)3e9371370cad9ae50d4b6cb6RebeccaPurplecolor (#3448)646b2e0a64642716342a0039ca8eaeeeb0c2a9b4a090d063scsslang (#3501)2aed9ce7Updated plugins
098e30009a4e725b91dea0c8Other
05ee042a866b302e9561a9abb85e1ada15272f769d603ef4v1.28.0Compare Source
New components
63806d57554ff324e2fe1f79ea8a0f404eb928c3a1340666dfef9b6133f2cf958a3fef6d0d49553ccbef9af71b1d6731Updated components
key,valuefor token names;attr-name,attr-valueas aliases (#3377)b94a664d7bda2bf1attr-nametoattribute; Useattr-nameas alias (#3381)cde0b5b2orkeyword (#3380)c30b736f&=and|=operators (#3395)8c4ae5a561c460e87ac84dda6a215fe0variableandoperatorregexes (#3398)8e59744bbeginkeyword (#3387)cf38d059function-name,range, andcell(#3391)ef0ec02atypetoclass-name(#3390)ce41434d[Ss]ymbolas a type (#3388)3916883atagtorecord(#3386)f8f953405617765fcb5229af4cb3d038recordfalse positives (#3348)3bd8fdb1ca78cde6bac368278e648dabkeytoproperty(#3394)1c533f4aneverreturn type + minor fix of named arguments (#3421)4ffab525readonlykeyword (#3349)4c3f1969499b1fa0@helperand inline C# inside attribute values (#3355)31a38d0cprivate,viewkeywords; Distinguishattributefromkeyword(#3389)d1a5ce30operatorregex (#3397)10ae6da3Updated plugins
17ed9160b53832cdf95dd1908a843a17Other
11c54624ead22e1e333bd590v1.27.0Compare Source
New components
3f8cc5a0Updated components
bcb2e2c8sectionfromkeywordtoselector(#3305)e46501b9headerforsection(#3304)deb3a97f8458c41f$(#3320)d6c53726441a1422operatorforpunctuation(#3306)2eb89e15Updated plugins
e002e78c1784b17582d0ca15Other
2cc4660bv1.26.0Compare Source
New components
b5a70e4c8476a9abd908e457ec25ba65ef53f021Updated components
\dfor[0-9](#3097)9fe2f93e929c33e0class-namestandard token (#3182)9f5e511dfa540ab7inoalias (#2990)5b7ce5e4c7809285nodeto known commands (#3291)4b19b502vcpkgcommand (#3282)b351bc69dockerandpodmancommands (#3237)8c5ed251d7017bebvariableand minor improvements (#3186)4cebf34cdirectivegreedy (#3112)5c412cbbchartoken (#3207)d85a64aechartoken (#3270)220bc40f9ed4cf6echartoken (#3188)1c88c7da7b34e65da943f2bb2f9672aa51e3ecc0symboltoken name (#3195)6af8a644dafdbdece1370357532212b2propertyforkey; alias withattr-name(#3272)bee6ad56builtinname (#3198)6add768b736c581d336edeeachartoken (#3271)b58cd722ee7ab563operatortoken and added tests (#3114)d359eeaechartoken and improvedstringandnumbertokens (#3208)f11b86e28494519esymbolalias for filter names (#3210)3d410670005ba469f41bcf2381920b623362fc7922d0c6ba0f1b58103d708b9715cb3b78c2afa59b5af16014chartoken (#3217)0a9f909cfa55492bcfb2e782numberpattern (#3149)5a24cbff3b2238fadfbb2020233415b823d9aec1chartoken (#3223)3a876df0baa95cabchartoken and improved string interpolation (#3225)563cd73e6b168a3b05e7ab04defun(#3130)e8f84a6c21a3c2d700f77a2ce9b856c8c6574e6bc1025aa6642d93ec7b72e0adchartoken and made some tokens greedy (#3231)2334b4b675331bea5bf6e35fdc1e808fcommentgreedy (#3234)969f152aadcc878455583fb2stringtoken (#3235)8e0e95f37bcc5da0314d6994a3905c04f053af13booleantoken (#3248)a5b6c5ebf22ea9f9ee62a080scopeandthis(#3243)59ef51dbe7ba877b5688f487data-typealternative (#3122)eeb13996d30a2da65ee8c557bacf9ae30390e644asmtoken (#3123)f3b25786commentgreedy (#3249)8ecef306matchandcase(soft) keywords (#3142)3f24dc7218bd101c2c63efa6stringgreedy (#3250)1e6dcb5118c92048parametertoken (#3090)0a313f4f809af0d94dde2e20ede55b2cchartoken (#3252)2069ab0c86028adbtype-definitionand use standard tokens correctly (#3253)4049e5c6chartoken (#3254)7d740c454eb81fa1chartoken (#3255)a7bb3001booleantoken (#3100)51382524acc0bc094e00cdddchartoken (#3256)58a65bfdafd77ed1d04d166disolatedkeyword (#3174)18c828a63ef71533regextoken (#3257)c56e4bf5e03a7c2491060fd6599e30eechartoken (#3260)e437325643124129aa73d448a28a86adffd8343fdeed35e3chartoken (#3264)c3f9fb7009a0e2baUpdated plugins
d38592c5drop-tokensoption class (#3166)b679cfe6highlightLinesfunction asPrism.plugins.highlightLines(#3086)9f4c0e74z-indexof.toolbarto 10 (#3163)1cac3559Updated themes
z-indexto make shadows visible in colored table cells (#3161)79f250f3a6a4ce7eOther
setLanguageutil function (#3167)b631949aa80a68badisableWorkerMessageHandler(#3088)213cf7be.html.testfiles for replace.jslanguage tests (#3148)2e834c8c5333e281TestCaseFileclass and generalizedrunTestCase(#3147)ae8888a0344d0b27a394a14d2f7f7364package.json: Addedengines.nodefield (#3108)798ee4f6package(-lock).json(#3098)8daebb4a[email protected](#3091)e6e1d5aed63d6c0e6f1d904a6c21b2f79d5424b6cefccdd10ecdbdce4433d7fe746da79bebd59e323755120031b4c1b8ea361e5ac5629706faedfe853d96eedcv1.25.0Compare Source
New components
746a4b1a87e5a376c1dce99823cd9b654f97b82bea776756e008ea05a1b67ce34fbdd2f8148c1eca4433ccfc8df825e06a356d25Updated components
748bb9acwithkeyword & improved record support (#2993)fdd291c0record,init, andnullablekeyword (#2991)9b561565fromkeyword (#2970)158f25d45de8947f8d0b74b59c8911bd693b7433emptykeyword (#2997) [fe3bc526]Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.