chore(deps): bump dompurify from 3.3.3 to 3.4.0
Open Source Applicant Tracking System (ATS)
Brought to you by:
joachimk
Originally created by: dependabot[bot]
Bumps dompurify from 3.3.3 to 3.4.0.
Sourced from dompurify's releases.
DOMPurify 3.4.0
Most relevant changes:
- Fixed a problem with
FORBID_TAGSnot winning overADD_TAGS, thanks@kodareef5- Fixed several minor problems and typos regarding MathML attributes, thanks
@DavidOliver- Fixed
ADD_ATTR/ADD_TAGSfunction leaking into subsequent array-based calls, thanks@1Jesper1- Fixed a missing
SAFE_FOR_TEMPLATESscrub inRETURN_DOMpath, thanks@bencalif- Fixed a prototype pollution via
CUSTOM_ELEMENT_HANDLING, thanks@trace37labs- Fixed an issue with
ADD_TAGSfunction form bypassingFORBID_TAGS, thanks@eddieran- Fixed an issue with
ADD_ATTRpredicates skipping URI validation, thanks@christos-eth- Fixed an issue with
USE_PROFILESprototype pollution, thanks@christos-eth- Fixed an issue leading to possible mXSS via Re-Contextualization, thanks
@researchatfluidattacksand others- Fixed an issue with closing tags leading to possible mXSS, thanks
@frevadiscor- Fixed a problem with the type dentition patcher after Node version bump
- Fixed freezing BS runs by reducing the tested browsers array
- Bumped several dependencies where possible
- Added needed files for OpenSSF scorecard checks
Published Advisories are here: https://github.com/cure53/DOMPurify/security/advisories?state=published
5b16e0b Getting 3.x branch ready for 3.4.0 release (#1250](https://github.com/href="https://redirect.github.com/cure53/DOMPurify/issues/1250">/issues/1250))Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Originally posted by: railway-app[bot]
🚅 Deployed to the reqcore-pr-142 environment in applirank
| Service | Status | Web | Updated (UTC) |
| :--- | :--- | :--- | :--- |
| applirank | ✅ Success (View Logs) | | Apr 16, 2026 at 5:00 am |