Skip to content

chore(deps): update dependency prismjs to v1.30.0 [security] - #180

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-prismjs-vulnerability
Open

chore(deps): update dependency prismjs to v1.30.0 [security]#180
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-prismjs-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
prismjs 1.29.01.30.0 age confidence

PrismJS DOM Clobbering vulnerability

CVE-2024-53382 / GHSA-x7hr-w5r2-h6wg

More information

Details

Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.

Severity

  • CVSS Score: 4.9 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

PrismJS/prism (prismjs)

v1.30.0

Compare Source

What's Changed

New Contributors

Full Changelog: PrismJS/prism@v1.29.0...v1.30.0


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown

Preview site

pr-180: https://pr-180--stuartclark.netlify.app

Updated 2026-09-09T23:38:51Z

@codecov

codecov Bot commented Sep 9, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 99.77%. Comparing base (5cf6028) to head (bec6d2e).

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #180   +/-   ##
=======================================
  Coverage   99.77%   99.77%           
=======================================
  Files          81       81           
  Lines        1340     1340           
  Branches      332      332           
=======================================
  Hits         1337     1337           
  Misses          3        3           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown

✅ Lighthouse Audit · unknown

All pages within budget — 13 pages scanned.

Route FCP LCP CLS TBT Perf
/ 2.8s 3.0s 0.009 95.000 0.89
/about 2.6s 3.1s 0.178 4.500 0.82
/community 2.6s 2.7s 0.016 3.000 0.92
/open-source 2.7s 4.8s 0.000 0.000 0.78
/writing 2.7s 2.9s 0.000 20.000 0.91
/writing/custom-formatters-410-20260731 2.9s 3.4s 0.063 0.000 0.86
/writing/decoupling-configuration-config-pages-20220412 2.7s 3.0s 0.015 0.000 0.90
/writing/drupal-site-settings-over-jsonapi-consumer-20260826 2.9s 4.1s 0.159 0.000 0.75
/writing/druxt-drupal-13x-resource-list-yours-20260909 3.2s 4.1s 0.058 0.000 0.80
/writing/field-tokens-200-20260722 2.6s 2.8s 0.019 0.000 0.92
/writing/hello-world-20211126 2.9s 3.0s 0.142 0.000 0.84
/writing/jsonapi-views-120-20260812 2.6s 2.8s 0.005 0.000 0.92
/writing/layout-paragraphs-module-20220301 2.7s 2.7s 0.055 0.000 0.91

Thresholds: FCP ≤ 3.5s, LCP ≤ 5.0s, CLS ≤ 0.25, TBT ≤ 600.000, Perf ≥ 0.75

@renovate
renovate Bot force-pushed the renovate/npm-prismjs-vulnerability branch from f74021e to bec6d2e Compare September 9, 2026 23:36
@coderabbitai

coderabbitai Bot commented Sep 9, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 337dddcc-b689-45f3-bcb5-93787108166a

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants