chore(deps): update dependency prismjs to v1.21.0 [security] - abandoned #191
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.16.0->1.21.0GitHub Vulnerability Alerts
CVE-2020-15138
Impact
The easing preview of the Previewers plugin has an XSS vulnerability that allows attackers to execute arbitrary code in Safari and Internet Explorer.
This impacts all Safari and Internet Explorer users of Prism >=v1.1.0 that use the Previewers plugin (>=v1.10.0) or the Previewer: Easing plugin (v1.1.0 to v1.9.0).
Patches
This problem is patched in v1.21.0.
Workarounds
To workaround the issue without upgrading, disable the easing preview on all impacted code blocks. You need Prism v1.10.0 or newer to apply this workaround.
References
The vulnerability was introduced by this commit on Sep 29, 2015 and fixed by Masato Kinugawa (#2506).
For more information
If you have any questions or comments about this advisory, please open an issue.
Release Notes
PrismJS/prism
v1.21.0Compare Source
New components
3fcce6fe3a127c7dde21eb64398e2943649e51e5ed8fff9187a5c7aeae0327b3bd4d8165d0c1c70d053016ef22eb5cad8704cdfb1093ceb3cde5b0facaec5e30ed1df1e1Updated components
9782cfe67a554b5f⍥(#2409)0255cb6aformatbuilt-in (#2450)7c66cfc4ddf3cc624fe03676composercommand (#2298)044dd271f0f8210c8a72fa6ffdcf7ed27f341fc12a2e79ed8e9d161ce3fe9040enum classclass names (#2342)30b4e254537a9e80964de5a1classandidpatterns (#2359)fdbc4473attr-{name,value}tokens and added tokens for combinators and selector lists (#2373)e523f5d04172ab6fprefixtoken (#2281)fd432a5b37273a6f0c30c582etaalias (#2282)0cfb6c5f33e49956de8ed16d9e64c62ed6055771namespacetoken (#2295)62e184bb032910ba4f55052fget/setand parameter detection (#2387)ed715158b28f21b72805ae35158caf5281cf2344ktandktsaliases (#2474)67f97e2e9c7bc820attr-equalsalias for the attribute=sign (#2350)96a0116eab1e34aeeb70070dobjcalias (#2331)67c6b7affec39bcf939a17c47f948ecbc93244768a72830arpyalias (#2385)4935b5caregexandstringpatterns (#2354)b526e8c02ff40fe0194c5429278316caa0a9f1efproc groovyandproc lua(#2392)475a59031e3f542b1946918ad2541d54e27e65afac297ba59a49f78fsolalias (#2382)6352213aRETURNINGkeyword (#2476)bea7a5856d663b6e2c10ef8a0d65d6c9b6093339assertskeyword and other improvements (#2280)a197cfcd78161d60untilkeyword (#2423)a13ee8d9ba5ac1daUpdated plugins
afea17d9a36e96aba3416bf3data-dependenciesand extensions (#2326)1654b25f5cdc32518c9c2896e6b2c6fceb82e804b96ed225lineNumberWrapperis null (#2337)4b61661d_resizeElementfunction (#2288)893f2a798bba4880Prism.languages.markup(#2444)af132dd3Updated themes
7109c18coperatortokens as intentional (#2309)937e269106495f90Other
cb6349e2402852034ff555be10f4327505c9f20bnpm run buildcommand (#2356)ff74a610inlineRegexSource(#2296)abb800dd11053193premergetask (#2357)5ff7932be756be3f681adeef48fac3b2a3758728583e7eb5components.json(#2370)e416341f10ca6433consolein VM context (#2353)b4ed5deddfa5498a91fdd0b1ce0fa227a0efa40b453079bf447429f0ad9c13e255bf7ec1v1.20.0Compare Source
New components
b24f73489227853fbf4f7bfaf941102e43efde2e8119e57b15983d52Updated components
328d0e0e57eebced674f4b35commentpattern (#2229)fa630726947a55bd42b15463462ad57eurl()containing "@" (#2272)504a63ba2e0eff76?(#2182)5450e24crecordkeyword (#2185)47910b5c73c8a37626626ded3b42536ec5de5aa87d8ff7eabd16bd57a7d67ca35362ba166124c974New plugins
be909b18Updated plugins
8d2c5a3e3c043338data-toolbar-orderis now inherited (#2205)238f1163Other
String.propotype.replacecalls for literal strings5d7aab56matchGrammar(#1909)2d4c94cdToken.stringify(#2171)f683972e984e5d2ee635260b67afc5ad81e1c3dd1e3070a27d03ece41f7a245cc917a8caa82770f8prism-liquibaseBash language extension. (#2191)0bf73dc76232878be9dab85ev1.19.0Compare Source
New components
694a81b8694a81b8c40d96c6Updated components
:and improved thevariablepattern (#2172)ef4d29d91f3f8929a23d8f84d7ad48f92a570fd424c8f833fd857e7b$a valid character for attribute names (#2144)f018cf047f1c55b7401d4b0299d979a0Updated plugins
543f04d7Updated themes
.tokenselector (#2161)86780457Other
a06aca060b539136loadLanguages(#2147)191b4116getLoader(#2151)199bdcaee5678a000c2fe40559068d67v1.18.0Compare Source
New components
aaaa29a83fdb7d55aaf13aa6631f1e340b771c909f7225862f3da7e8e2b99f40f31946b3f7eaa618cc2cf3f7c42f877dcfac94ec508d57aca7cf56b7Updated components
7db0cab3ad3fa443717ace02f3c6ba59899574eb32a4c4228ea685b8ebe363f4010a0157fb618331::operator (#2101)ee7fdbeea7b95dd3fdb7de0d:as an operator (#2073)0e5c48d1d03d19b499994c585b8a16d9baa78774trueandfalsebooleans (#2098)68d1c472f460eafc3640b3f207020c7aproc-argstoken by removing backreferences from string pattern (#2013)af5a36ae076f61551aabcd178ccd258bundefined(#2088)c8b48b9fUpdated plugins
365faade8403e453a7f70090dab7998ec6c62a69Other
53f07b1b6cd0738a0fd062d5a3785ec92d858e0a174ed103e864d518manualflag (#1957)d49f0f26currentScript(#2104)2108c60f2f495905.githubfolder to npm ignore (#2052)1af89e063af5d744c187e229007c9af43fda5c957a4a0c7c5d07aa7ccdfa60ac8bcc1b8556a8711c8a572af55c68a5563509f3e57cb65eec9908ca69v1.17.1Compare Source
Other
c2229ec2v1.17.0Compare Source
New components
bb84f98c73d964bec88442865d992fc5858201c7473f7fbd96044979c93c066bNew plugins
e7702ae1Updated components
363281b3csalias (#1899)a81645593de29e72urlinside (#1874)f0a1066974050c68even&oddkeywords ton-thpattern (#1872)5e5a3e00d58d2aebc88442867bd083276068bf18c13d6e7dsregex flag (#1846)9e164935e2683959cbe05ec3structkeyword (#1941)feb1b6f5InfandNaNas constants (#1921)2141129finkeyword (#1918)feb3187f5ad58a756f53f74905823e88b9ec6fd811903721cedb8e84returnkeyword (#1943)2f39de97de10bd1d8b5d67a3asyncandawaitkeywords. (#1882)4faa3314a42b15574b6b6e8be8811d223e1812414a2c90c1Updated plugins
452d5c7deb28b62bb19f512fc24831b579880197acceb3b5Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate. View repository job log here.