Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jul 15, 2024

Bumps prosemirror-model from 1.19.4 to 1.22.1.

Changelog

Sourced from prosemirror-model's changelog.

1.22.1 (2024-07-14)

Bug fixes

Add code to DOMSerializer that rejects DOM output specs when they originate from attribute values, to protect against XSS attacks that use corrupt attribute input.

1.22.0 (2024-07-14)

New features

Attribute specs now support a validate property that can be used to provide a validation function for the attribute, to guard against corrupt JSON input.

1.21.3 (2024-06-26)

Bug fixes

Fix an issue where parse rules for CSS properties that were shorthands for a number of more detailed properties weren't matching properly.

1.21.2 (2024-06-25)

Bug fixes

Make sure resolved positions (and thus the document and schema hanging off them) don't get kept in the cache when their document can be garbage-collected.

1.21.1 (2024-06-03)

Bug fixes

Improve performance and accuracy of DOMParser style matching by using the DOM's own style object.

1.21.0 (2024-05-06)

New features

The new linebreakReplacement property on node specs makes it possible to configure a node type that setBlockType will convert to and from line breaks when appropriate.

1.20.0 (2024-04-08)

New features

The ParseRule type is now a union of TagParseRule and StyleParseRule, with more specific types being used when appropriate.

Commits
  • 3360cdc Mark version 1.22.1
  • 6e977d7 Add code to actively guard against corrupted-attribute XSS attacks
  • 1357ec7 Mark version 1.22.0
  • fca6ef9 Add attribute value validation
  • 751134c Mark version 1.21.3
  • 1f0c6ed Directly query style props used in parse rules
  • 68c3cd5 Mark version 1.21.2
  • 54de8c0 Use a WeakMap in the resolved position cache to avoid leaking
  • cde085e Add some missing type declarations
  • d326751 Properly mark Node.findIndex as internal
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [prosemirror-model](https://github.com/prosemirror/prosemirror-model) from 1.19.4 to 1.22.1.
- [Changelog](https://github.com/ProseMirror/prosemirror-model/blob/master/CHANGELOG.md)
- [Commits](ProseMirror/prosemirror-model@1.19.4...1.22.1)

---
updated-dependencies:
- dependency-name: prosemirror-model
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Jul 15, 2024
@github-actions github-actions bot enabled auto-merge (squash) July 15, 2024 12:14
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Jul 22, 2024

Superseded by #346.

@dependabot dependabot bot closed this Jul 22, 2024
auto-merge was automatically disabled July 22, 2024 13:07

Pull request was closed

@dependabot dependabot bot deleted the dependabot/npm_and_yarn/prosemirror-model-1.22.1 branch July 22, 2024 13:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant