fix: sanitizer svg to avoid xss (#16606)

This commit is contained in:
Joel
2025-03-24 14:36:07 +08:00
committed by GitHub
parent 9701b573e0
commit 16b6ffd915
4 changed files with 21 additions and 24 deletions

11
web/pnpm-lock.yaml generated
View File

@@ -121,6 +121,9 @@ importers:
decimal.js:
specifier: ^10.4.3
version: 10.4.3
dompurify:
specifier: ^3.2.4
version: 3.2.4
echarts:
specifier: ^5.5.1
version: 5.5.1
@@ -4299,8 +4302,8 @@ packages:
resolution: {integrity: sha512-GrwoxYN+uWlzO8uhUXRl0P+kHE4GtVPfYzVLcUxPL7KNdHKj66vvlhiweIHqYYXWlw+T8iLMp42Lm67ghw4WMQ==}
engines: {node: '>= 4'}
dompurify@3.2.3:
resolution: {integrity: sha512-U1U5Hzc2MO0oW3DF+G9qYN0aT7atAou4AgI0XjWz061nyBPbdxkfdhfy5uMgGn6+oLFCfn44ZGbdDqCzVmlOWA==}
dompurify@3.2.4:
resolution: {integrity: sha512-ysFSFEDVduQpyhzAob/kkuJjf5zWkZD8/A9ywSp1byueyuCfHamrCBa14/Oc2iiB0e51B+NpxSl5gmzn+Ms/mg==}
domutils@2.8.0:
resolution: {integrity: sha512-w96Cjofp72M5IIhpjgobBimYEfoPjx1Vx0BSX9P30WBdZW2WIKU0T1Bd0kz2eNZ9ikjKgHbEyKx8BB6H1L3h3A==}
@@ -13070,7 +13073,7 @@ snapshots:
dependencies:
domelementtype: 2.3.0
dompurify@3.2.3:
dompurify@3.2.4:
optionalDependencies:
'@types/trusted-types': 2.0.7
@@ -15688,7 +15691,7 @@ snapshots:
d3-sankey: 0.12.3
dagre-d3-es: 7.0.11
dayjs: 1.11.13
dompurify: 3.2.3
dompurify: 3.2.4
katex: 0.16.21
khroma: 2.1.0
lodash-es: 4.17.21