Skip to content

[Cycode] Fix for vulnerable manifest file dependency - dompurify updated to version 3.4.0#80

Open
cycode-security[bot] wants to merge 1 commit into
mainfrom
cycode-fix-suggestion-manifest-dependency-update-9dcd6407-d6c1-419f-8e2d-01c0543a7a65
Open

[Cycode] Fix for vulnerable manifest file dependency - dompurify updated to version 3.4.0#80
cycode-security[bot] wants to merge 1 commit into
mainfrom
cycode-fix-suggestion-manifest-dependency-update-9dcd6407-d6c1-419f-8e2d-01c0543a7a65

Conversation

@cycode-security

@cycode-security cycode-security Bot commented Apr 22, 2026

Copy link
Copy Markdown

Cycode Vulnerable Dependencies Update

This pull request updates the following manifest file:

File Path Number of packages to update
ui/app/package.json 1

📂 ui/app/package.json

1 package will be updated to resolve vulnerabilities:

Package Name Current Version Updated Version
dompurify 3.2.4 3.4.0

Warning

Lock file generation failed for one or more manifest files in this pull request. Please regenerate the lock file manually before merging.


Note

Low Risk
Low-risk dependency bump intended to address a known vulnerability, but it may be risky to merge as-is because the repo lockfile(s) appear not to be updated and could keep resolving dompurify to the older version.

Overview
Bumps the UI app dependency dompurify from ^3.2.4 to ^3.4.0 in ui/app/package.json to address a reported vulnerability.

No code changes are included; ensure the relevant lockfile(s) are regenerated/updated so installs don’t continue to pin [email protected].

Reviewed by Cursor Bugbot for commit 87d2dca. Bugbot is set up for automated code reviews on this repo. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants