-
- Downloads
Upgrade mermaid to prevent xss attack
Update mermaid to avoid xss surface area. The newer release restricts script tags to be embedded in mermaid blocks.
Showing
- app/assets/javascripts/behaviors/markdown/render_mermaid.js 1 addition, 0 deletionsapp/assets/javascripts/behaviors/markdown/render_mermaid.js
- changelogs/unreleased/security-xss-mermaid-12-1.yml 5 additions, 0 deletionschangelogs/unreleased/security-xss-mermaid-12-1.yml
- package.json 2 additions, 2 deletionspackage.json
- spec/features/issues/user_comments_on_issue_spec.rb 3 additions, 2 deletionsspec/features/issues/user_comments_on_issue_spec.rb
- yarn.lock 1631 additions, 314 deletionsyarn.lock
This diff is collapsed.
Please register or sign in to comment