fix(deps): update dependency prismjs to v1.24.0 [security] #366
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.23.0->1.24.0GitHub Vulnerability Alerts
CVE-2021-32723
Some languages before 1.24.0 are vulnerable to Regular Expression Denial of Service (ReDoS).
Impact
When Prism is used to highlight untrusted (user-given) text, an attacker can craft a string that will take a very very long time to highlight. Do not use the following languages to highlight untrusted text.
Other languages are not affected and can be used to highlight untrusted text.
Patches
This problem has been fixed in Prism v1.24.
References
Release Notes
PrismJS/prism (prismjs)
v1.24.0Compare Source
New components
b0a6ec853f7d74537e5f78ff41e25d3cf9b695281f91868e99a21dc5bf4e7ba9e93144157e51b99c3419fb772bc6475bf84c49c51a2347a318c67b491b63cd01e38986f9fd1081d2bbc77d1972962701c4f6b2ccUpdated components
regexp/no-dupe-disjunctions(#2952)f471d2d779d22182d85e30daea82478dfc2a3334e4ad22ade5cfdb4a::punctuation (#2814)3df62fd088fa72cfd0bcd07493dd83c2114e4626e6c0d298defdelagatekeyword and highlighting for function/module names (#2709)59f725d7a5d7178cdefinition-queryanddefinition-mutationtokens (#2964)bfd7fded34f24ac9hbsalias (#2874)439763511dfc82716183fd9b4e7b2a8242d24fa24ec7535cab7c9953415651a09c610ae6022f90a0abab9104cf28d1b2ac1d12f945ec4a88e9477d83wraphook (#2719)2b355c988dbbbb355943f4cb87d79390cf3755cbfnkeyword (#2858)e0ee93f17e8cd40d8019e2f6f79b0eef04ef309c01af04ed9f59f52d30b0444finlinepattern (#2946)a7656de620b77bff3786f396f08c2f7f0e61a7e11c6c0bf3cda976b1c83fd0b8ILIKEoperator (#2704)6e34771fsomekeyword (#2756)cf354ef5fe98d53631cc2142a68f1fb6REMis no longer highlighted as a keyword in comments (#2823)ebbbfd47e32e043b459365ecUpdated plugins
4b55bd6a96335642c81c3319d5e14e1aclipboard.writeTextnot working inside iFrames (#2826)01b7b6f74d7f75b02cb909e153d34b22ccc73ab7classListinstead ofclassName(#2787)d298d46eOther
tabindexto code blocks to enable keyboard navigation (#2799)dbf70515b37987d3970674cfnpm-run-allto clean up test command (#2938)5d3d80887cd9e794b77317c545b0e82a0feb266fad9878ad--languagefor patterns tests (#2929)a62ef7968dbf1217a9a199b64492c5ce531514045bc405e799f3ddcd--insertand--updateparameters to language test (#2809)4c8b855dcomponents.jsontests (#2758)933af8057a790bf9npm ci(#2899)91f3aaedcb220168266cc700my.cdnin code sample with Handlebars-like placeholder (#2906)8047118138f1d2899b784ebfa1209930ec9767d61506f345Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate. View repository job log here.