Skip to content

chore(deps): update dependency prismjs to v1.30.0 [security] #32227

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 6 commits into from
Aug 18, 2025

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Aug 13, 2025

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
prismjs 1.27.0 -> 1.30.0 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2024-53382

Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.


Release Notes

PrismJS/prism (prismjs)

v1.30.0

Compare Source

What's Changed

New Contributors

Full Changelog: PrismJS/prism@v1.29.0...v1.30.0

v1.29.0

Compare Source

New components
Updated components
Updated plugins
Other

v1.28.0

Compare Source

New components
Updated components
Updated plugins
Other

Configuration

📅 Schedule: Branch creation - "" in timezone America/New_York, Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@cypress-app-bot
Copy link
Collaborator

See the guidelines for reviewing dependency updates for info on how to review dependency update PRs.

@renovate renovate bot force-pushed the renovate/npm-prismjs-vulnerability branch 18 times, most recently from f01661f to fe3b9e3 Compare August 15, 2025 19:58
@renovate renovate bot force-pushed the renovate/npm-prismjs-vulnerability branch from fe3b9e3 to 1095123 Compare August 15, 2025 20:09
@renovate renovate bot force-pushed the renovate/npm-prismjs-vulnerability branch from 1095123 to 921f044 Compare August 15, 2025 20:15
@renovate renovate bot force-pushed the renovate/npm-prismjs-vulnerability branch from 921f044 to 691a54e Compare August 15, 2025 20:36
@jennifer-shehane jennifer-shehane self-requested a review August 15, 2025 20:38
@jennifer-shehane jennifer-shehane self-assigned this Aug 15, 2025
Copy link
Contributor Author

renovate bot commented Aug 15, 2025

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

Copy link

cypress bot commented Aug 15, 2025

cypress    Run #64674

Run Properties:  status check passed Passed #64674  •  git commit 3bf097c3c5: Merge branch 'renovate/npm-prismjs-vulnerability' of https://github.com/cypress-...
Project cypress
Branch Review renovate/npm-prismjs-vulnerability
Run status status check passed Passed #64674
Run duration 19m 23s
Commit git commit 3bf097c3c5: Merge branch 'renovate/npm-prismjs-vulnerability' of https://github.com/cypress-...
Committer Jennifer Shehane
View all properties for this run ↗︎

Test results
Tests that failed  Failures 0
Tests that were flaky  Flaky 8
Tests that did not run due to a developer annotating a test with .skip  Pending 1101
Tests that did not run due to a failure in a mocha hook  Skipped 0
Tests that passed  Passing 26543
View all changes introduced in this branch ↗︎
UI Coverage  45.14%
  Untested elements 187  
  Tested elements 158  
Accessibility  97.71%
  Failed rules  4 critical   8 serious   2 moderate   2 minor
  Failed elements 110  

@jennifer-shehane jennifer-shehane merged commit 86b6865 into develop Aug 18, 2025
84 of 90 checks passed
@jennifer-shehane jennifer-shehane deleted the renovate/npm-prismjs-vulnerability branch August 18, 2025 15:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants