Skip to content

[Snyk] Upgrade isomorphic-dompurify from 3.6.0 to 3.7.1#31

Open
Madhuri-cs wants to merge 1 commit intomainfrom
snyk-upgrade-1fd4cfdf4e1042e84f614d11536c5ef6
Open

[Snyk] Upgrade isomorphic-dompurify from 3.6.0 to 3.7.1#31
Madhuri-cs wants to merge 1 commit intomainfrom
snyk-upgrade-1fd4cfdf4e1042e84f614d11536c5ef6

Conversation

@Madhuri-cs
Copy link
Copy Markdown

snyk-top-banner

Snyk has created this PR to upgrade isomorphic-dompurify from 3.6.0 to 3.7.1.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 2 versions ahead of your current version.

  • The recommended version was released 23 days ago.

Release notes
Package name: isomorphic-dompurify
  • 3.7.1 - 2026-03-24

    Bug Fix

    • Fixed missing browser type declarationsbrowser.d.ts and browser.d.mts were not included in the 3.7.0 published package due to a race condition in the build process. This caused TS7016: Could not find a declaration file for module 'isomorphic-dompurify' errors in tsgo and TypeScript 6 when resolving through the default (browser) exports condition. (#411)

    Thanks to @ asterikx and @ ElPrudi for their help with the issue.

  • 3.7.0 - 2026-03-24

    TypeScript 6 compatibility fixes:

    • Add explicit type annotation for sanitize to satisfy TS6
    • Silence baseUrl deprecation warning from tsup dts build in TS6

    Dependency updates:

    • bump typescript from 5.9.3 to 6.0.2
    • bump vitest from 4.1.0 to 4.1.1
  • 3.6.0 - 2026-03-21

    Dependency updates:

    • bump jsdom from 29.0.0 to 29.0.1
    • bump @ types/jsdom from 28.0.0 to 28.0.1
    • bump @ biomejs/biome from 2.4.7 to 2.4.8
from isomorphic-dompurify GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade isomorphic-dompurify from 3.6.0 to 3.7.1.

See this package in npm:
isomorphic-dompurify

See this project in Snyk:
https://app.snyk.io/org/contentstack-devex/project/ed870e6f-e80d-4646-8917-16d2788bd462?utm_source=github&utm_medium=referral&page=upgrade-pr
@Madhuri-cs Madhuri-cs requested a review from a team as a code owner April 15, 2026 23:55
@github-actions
Copy link
Copy Markdown

🔒 Security Scan Results

ℹ️ Note: Only vulnerabilities with available fixes (upgrades or patches) are counted toward thresholds.

Check Type Count (with fixes) Without fixes Threshold Result
🔴 Critical Severity 2 0 10 ✅ Passed
🟠 High Severity 5 0 25 ✅ Passed
🟡 Medium Severity 4 20 500 ✅ Passed
🔵 Low Severity 0 0 1000 ✅ Passed

⏱️ SLA Breach Summary

⚠️ Warning: The following vulnerabilities have exceeded their SLA thresholds (days since publication).

Severity Breaches (with fixes) Breaches (no fixes) SLA Threshold (with/no fixes) Status
🔴 Critical 0 0 15 / 30 days ✅ Passed
🟠 High 0 0 30 / 120 days ✅ Passed
🟡 Medium 0 18 90 / 365 days ⚠️ Warning
🔵 Low 0 0 180 / 365 days ✅ Passed

ℹ️ Vulnerabilities Without Available Fixes (Informational Only)

The following vulnerabilities were detected but do not have fixes available (no upgrade or patch). These are excluded from failure thresholds:

  • Critical without fixes: 0
  • High without fixes: 0
  • Medium without fixes: 20
  • Low without fixes: 0

⚠️ BUILD PASSED WITH WARNINGS - SLA breaches detected for issues without available fixes

Consider reviewing these vulnerabilities when fixes become available.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants