-
Notifications
You must be signed in to change notification settings - Fork 43
chore(deps): update dependency svelte to v4.2.19 [security] #166
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
renovate
wants to merge
1
commit into
master
Choose a base branch
from
renovate/npm-svelte-vulnerability
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
size-limit report 📦
|
e9e205b to
fef84fb
Compare
fef84fb to
f27056a
Compare
f27056a to
89a7012
Compare
ead036d to
c4153f0
Compare
c4153f0 to
39022b7
Compare
39022b7 to
cbbb96b
Compare
cbbb96b to
873af66
Compare
873af66 to
d675e51
Compare
d675e51 to
f251bf1
Compare
f251bf1 to
db9de17
Compare
db9de17 to
64c5ca2
Compare
64c5ca2 to
6d807b8
Compare
f0fb67e to
c3ff0e9
Compare
c3ff0e9 to
9ee356d
Compare
9ee356d to
8ac835f
Compare
8ac835f to
fd3fb53
Compare
fd3fb53 to
77ae3ff
Compare
77ae3ff to
d0bec6c
Compare
d0bec6c to
76530db
Compare
76530db to
a9bdfa1
Compare
a9bdfa1 to
ababdd2
Compare
ababdd2 to
021d2d7
Compare
c5b631f to
c182c81
Compare
c182c81 to
87c9cb5
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
None yet
0 participants
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.2.9→4.2.19GitHub Vulnerability Alerts
CVE-2024-45047
Summary
A potential XSS vulnerability exists in Svelte for versions prior to 4.2.19.
Details
Svelte improperly escapes HTML on server-side rendering. It converts strings according to the following rules:
"->"&->&<-><&->&The assumption is that attributes will always stay as such, but in some situation the final DOM tree rendered on browsers is different from what Svelte expects on server-side rendering. This may be leveraged to perform XSS attacks. More specifically, this can occur when injecting malicious content into an attribute within a
<noscript>tag.PoC
A vulnerable page (
+page.svelte):If a user accesses the following URL,
then,
alert(123)will be executed.Impact
XSS, when using an attribute within a noscript tag
Release Notes
sveltejs/svelte (svelte)
v4.2.19Compare Source
Patch Changes
fix: ensure typings for
<svelte:options>are picked up (#12902)fix: escape
<in attribute strings (#12989)v4.2.18Compare Source
Patch Changes
v4.2.17Compare Source
Patch Changes
v4.2.16Compare Source
Patch Changes
v4.2.15Compare Source
Patch Changes
v4.2.14Compare Source
Patch Changes
v4.2.13Compare Source
Patch Changes
v4.2.12Compare Source
Patch Changes
svelte:componentprops when there are spread props (#10604)v4.2.11Compare Source
Patch Changes
connectedCallback(#10466)v4.2.10Compare Source
Patch Changes
fix: add
scrollendevent type (#10336)fix: add
fetchpriorityattribute type (#10390)fix: Add
miter-clipandarcstostroke-linejoinattribute (#10377)fix: make inline doc links valid (#10366)
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.