From 8362e52751b2c2cff3a5161f7482e067ae609f86 Mon Sep 17 00:00:00 2001 From: "hash-worker[bot]" <180894564+hash-worker[bot]@users.noreply.github.com> Date: Fri, 19 Jun 2026 11:08:56 +0000 Subject: [PATCH 1/2] Update npm package `dompurify` to v3.4.11 [SECURITY] --- apps/hash-frontend/package.json | 2 +- package.json | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/apps/hash-frontend/package.json b/apps/hash-frontend/package.json index 77a4485ff4b..093984c1ac2 100644 --- a/apps/hash-frontend/package.json +++ b/apps/hash-frontend/package.json @@ -76,7 +76,7 @@ "buffer": "6.0.3", "clsx": "2.1.1", "date-fns": "4.1.0", - "dompurify": "3.4.0", + "dompurify": "3.4.11", "dotenv-flow": "3.3.0", "elkjs": "0.11.0", "emoji-mart": "5.6.0", diff --git a/package.json b/package.json index 005eae6eadd..1a5b202cb82 100644 --- a/package.json +++ b/package.json @@ -87,7 +87,7 @@ "@tldraw/tlschema@npm:2.0.0-alpha.12": "patch:@tldraw/tlschema@npm%3A2.0.0-alpha.12#~/.yarn/patches/@tldraw-tlschema-npm-2.0.0-alpha.12-13bf88407b.patch", "blockprotocol@npm:0.0.10": "patch:blockprotocol@npm%3A0.0.12#~/.yarn/patches/blockprotocol-npm-0.0.12-2558a31f0a.patch", "canvas": "3.2.0", - "dompurify": "3.4.0", + "dompurify": "3.4.11", "fast-xml-parser": "5.7.0", "http-proxy-middleware@npm:^2.0.9": "patch:http-proxy-middleware@npm%3A3.0.5#~/.yarn/patches/http-proxy-middleware-npm-3.0.5-5c57f2e983.patch", "jsondiffpatch": "0.7.2", From d7d5f2f27d68431a94cf512720169c3ef8eed3ea Mon Sep 17 00:00:00 2001 From: Ciaran Morinan Date: Wed, 24 Jun 2026 09:11:09 +0100 Subject: [PATCH 2/2] yarn --- yarn.lock | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/yarn.lock b/yarn.lock index 54a5e1b8fa0..fba91692c09 100644 --- a/yarn.lock +++ b/yarn.lock @@ -650,7 +650,7 @@ __metadata: buffer: "npm:6.0.3" clsx: "npm:2.1.1" date-fns: "npm:4.1.0" - dompurify: "npm:3.4.0" + dompurify: "npm:3.4.11" dotenv-flow: "npm:3.3.0" elkjs: "npm:0.11.0" emoji-mart: "npm:5.6.0" @@ -23241,15 +23241,15 @@ __metadata: languageName: node linkType: hard -"dompurify@npm:3.4.0": - version: 3.4.0 - resolution: "dompurify@npm:3.4.0" +"dompurify@npm:3.4.11": + version: 3.4.11 + resolution: "dompurify@npm:3.4.11" dependencies: "@types/trusted-types": "npm:^2.0.7" dependenciesMeta: "@types/trusted-types": optional: true - checksum: 10c0/5593ac44ee20b9aa521c2120884effc98927fb9128c548183c75e79e0a04357c62ee913a049a267c8f396cb8c9d520ecf72562826c5524c46d4fe03c12063638 + checksum: 10c0/31439481c7e8fc3805d40c376936fd66936620fb1b1a31a2ec097f6165412c37f2d868e082c9ceba62bb37661c1ea132a5db4d5213434317e30df68d4aca9cc9 languageName: node linkType: hard