Skip to content

Commit 4565408

Browse files
feat(deps): Bump svgo from 4.0.2 to 4.1.0 (#24220)
Bumps [svgo](https://github.com/svg/svgo) from 4.0.2 to 4.1.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/svg/svgo/releases">svgo's releases</a>.</em></p> <blockquote> <h2>v4.1.0</h2> <p>This minor release upgrades the SAX parser and introduces stricter XML validation. It also includes important security hardening for <code>removeScripts</code>, dependency updates, and improvements to the test and regression infrastructure.</p> <h3>Support SVGO</h3> <p>If SVGO is valuable to you or your organization, please consider <a href="https://opencollective.com/svgo">supporting the project on OpenCollective</a>. Your sponsorship helps fund ongoing maintenance and security work.</p> <h3>Stricter XML validation</h3> <p>SVGO now uses <a href="https://www.npmjs.com/package/sax"><code>sax</code> 1.6.1</a>, upgraded from 1.5.0 (<a href="https://redirect.github.com/svg/svgo/pull/2257">#2257</a>).</p> <p>The new parser version validates numeric character references against the ranges permitted by XML. Invalid references are now rejected in both text and attributes, including:</p> <ul> <li>disallowed control characters such as <code>&amp;[#1](https://github.com/svg/svgo/issues/1);</code>, <code>&amp;#xB;</code>, and <code>&amp;#x1F;</code>;</li> <li>UTF-16 surrogate code points such as <code>&amp;#xD800;</code>;</li> <li>invalid XML code points such as <code>&amp;#xFFFF;</code>.</li> </ul> <p>Valid boundary values—including <code>U+0020</code>, <code>U+D7FF</code>, <code>U+E000</code>, <code>U+FFFD</code>, and characters through <code>U+10FFFF</code>—remain supported.</p> <p>Parser failures are consistently exposed as <code>SvgoParserError</code> errors with an <code>Invalid character entity</code> reason.</p> <p>This is an intentional behavior change: malformed SVGs that were previously accepted may now produce a parser error, while valid XML documents are unaffected.</p> <h3>Security</h3> <p>The <a href="https://svgo.dev/docs/plugins/removeScripts/"><code>removeScripts</code></a> plugin has been hardened against several script-execution bypasses:</p> <ul> <li>Filters executable <code>data:</code> URLs containing HTML, XHTML, or SVG documents while preserving inert data such as PNG images, and filters legacy <code>vbscript:</code> URLs (<a href="https://redirect.github.com/svg/svgo/pull/2263">#2263</a>).</li> <li>Sanitizes content inside SVG <code>&lt;foreignObject&gt;</code> elements by removing HTML event-handler attributes, <code>srcdoc</code>, and executable URLs from <code>action</code>, <code>data</code>, <code>formaction</code>, <code>href</code>, and <code>src</code>, while preserving non-executable HTML and visual content (<a href="https://redirect.github.com/svg/svgo/pull/2264">#2264</a>).</li> <li>Recognizes namespace-prefixed SVG <code>&lt;a&gt;</code> elements and removes ASCII tabs and newlines before checking URL schemes, preventing values such as <code>java&amp;[#9](https://github.com/svg/svgo/issues/9);script:</code> from bypassing detection while preserving elements in unrelated custom namespaces (<a href="https://redirect.github.com/svg/svgo/pull/2268">#2268</a>).</li> </ul> <p>These changes address:</p> <ul> <li><a href="https://github.com/svg/svgo/security/advisories/GHSA-4vpr-x523-8j87">GHSA-4vpr-x523-8j87</a></li> <li><a href="https://github.com/svg/svgo/security/advisories/GHSA-w27v-7q3p-w38r">GHSA-w27v-7q3p-w38r</a></li> </ul> <h3>Dependencies</h3> <ul> <li>Upgraded <code>css-select</code> to v6 and <code>css-what</code> to v7, and updated SVGO's custom selector adapter for <code>css-select</code> v6 (<a href="https://redirect.github.com/svg/svgo/pull/2244">#2244</a>).</li> </ul> <h3>Project maintenance</h3> <p><a href="https://github.com/TrySound"><code>@​TrySound</code></a> is back as an active SVGO maintainer.</p> <p>Many thanks to <a href="https://github.com/KTibow"><code>@​KTibow</code></a>, <a href="https://github.com/SethFalco"><code>@​SethFalco</code></a>, and <a href="https://github.com/XhmikosR"><code>@​XhmikosR</code></a> for maintaining and improving SVGO over the past several years.</p> <p><strong>Full Changelog:</strong> <a href="https://github.com/svg/svgo/compare/v4.0.2...v4.1.0">https://github.com/svg/svgo/compare/v4.0.2...v4.1.0</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/svg/svgo/commit/5765cbe4e0a930dca648c6b81d335b1522cd7375"><code>5765cbe</code></a> chore: prepare v4.1.0 release (<a href="https://redirect.github.com/svg/svgo/issues/2275">#2275</a>)</li> <li><a href="https://github.com/svg/svgo/commit/3db3ef33e409a0bc0fdaf255e46c908b00e93bc2"><code>3db3ef3</code></a> fix(removeScripts): handle anchor URL bypasses (<a href="https://redirect.github.com/svg/svgo/issues/2268">#2268</a>)</li> <li><a href="https://github.com/svg/svgo/commit/4e9b9aed2a4607cf28025871151421d5bfe86484"><code>4e9b9ae</code></a> chore: cache regression screenshots (<a href="https://redirect.github.com/svg/svgo/issues/2267">#2267</a>)</li> <li><a href="https://github.com/svg/svgo/commit/d55270ce17b99ebfe16e4fad028bd162187205a1"><code>d55270c</code></a> chore(regression): migrate comparison workers to Tinypool (<a href="https://redirect.github.com/svg/svgo/issues/2266">#2266</a>)</li> <li><a href="https://github.com/svg/svgo/commit/fd51e474a300417d9361d9302d596b1763146327"><code>fd51e47</code></a> fix(removeScripts): sanitize foreignObject content (<a href="https://redirect.github.com/svg/svgo/issues/2264">#2264</a>)</li> <li><a href="https://github.com/svg/svgo/commit/dcaf957c6eb34832844de11ef2792e3e0e8db5dd"><code>dcaf957</code></a> chore: optimize fixtures in a bounded worker pool (<a href="https://redirect.github.com/svg/svgo/issues/2265">#2265</a>)</li> <li><a href="https://github.com/svg/svgo/commit/a3542937d9c85debab04b1ff75207768caf8a058"><code>a354293</code></a> fix(removeScripts): filter executable data URLs (<a href="https://redirect.github.com/svg/svgo/issues/2263">#2263</a>)</li> <li><a href="https://github.com/svg/svgo/commit/4e0d2ac5e7abd5f12d650d3e4b4d2500d4944cc5"><code>4e0d2ac</code></a> ci(typecheck): return typechecking on CI</li> <li><a href="https://github.com/svg/svgo/commit/0b97fedd00a3001f1da616f61578c2c12e6cde1f"><code>0b97fed</code></a> test(typescript): drop tsd for vitest type testing API</li> <li><a href="https://github.com/svg/svgo/commit/f6e8ae1afb012c2b47675622728d76b9bfd734f5"><code>f6e8ae1</code></a> chore(pnpm): drop package.json#pnpm.onlyBuiltDependencies</li> <li>Additional commits viewable in <a href="https://github.com/svg/svgo/compare/v4.0.2...v4.1.0">compare view</a></li> </ul> </details> <details> <summary>Maintainer changes</summary> <p>This version was pushed to npm by <a href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new releaser for svgo since your current version.</p> </details> <br /> [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=svgo&package-manager=npm_and_yarn&previous-version=4.0.2&new-version=4.1.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/getsentry/sentry-javascript/network/alerts). </details> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Andrei Borza <andrei.borza@sentry.io>
1 parent 019c889 commit 4565408

1 file changed

Lines changed: 29 additions & 24 deletions

File tree

‎yarn.lock‎

Lines changed: 29 additions & 24 deletions
Original file line numberDiff line numberDiff line change
@@ -13364,16 +13364,16 @@ css-select@^4.1.3, css-select@^4.2.0:
1336413364
domutils "^2.8.0"
1336513365
nth-check "^2.0.1"
1336613366

13367-
css-select@^5.1.0:
13368-
version "5.1.0"
13369-
resolved "https://registry.yarnpkg.com/css-select/-/css-select-5.1.0.tgz#b8ebd6554c3637ccc76688804ad3f6a6fdaea8a6"
13370-
integrity sha512-nwoRF1rvRRnnCqqY7updORDsuqKzqYJ28+oSMaJMMgOauh3fvwHqMS7EZpIPqK8GL+g9mKxF1vP/ZjSeNjEVHg==
13367+
css-select@^6.0.0:
13368+
version "6.0.0"
13369+
resolved "https://registry.yarnpkg.com/css-select/-/css-select-6.0.0.tgz#7e63f09881ad118084091048ed543786dad96644"
13370+
integrity sha512-rZZVSLle8v0+EY8QAkDWrKhpgt6SA5OtHsgBnsj6ZaLb5dmDVOWUDtQitd9ydxxvEjhewNudS6eTVU7uOyzvXw==
1337113371
dependencies:
1337213372
boolbase "^1.0.0"
13373-
css-what "^6.1.0"
13374-
domhandler "^5.0.2"
13375-
domutils "^3.0.1"
13376-
nth-check "^2.0.1"
13373+
css-what "^7.0.0"
13374+
domhandler "^5.0.3"
13375+
domutils "^3.2.2"
13376+
nth-check "^2.1.1"
1337713377

1337813378
css-tree@^2.3.1:
1337913379
version "2.3.1"
@@ -13399,11 +13399,16 @@ css-tree@~2.2.0:
1339913399
mdn-data "2.0.28"
1340013400
source-map-js "^1.0.1"
1340113401

13402-
css-what@^6.0.1, css-what@^6.1.0:
13402+
css-what@^6.0.1:
1340313403
version "6.1.0"
1340413404
resolved "https://registry.yarnpkg.com/css-what/-/css-what-6.1.0.tgz#fb5effcf76f1ddea2c81bdfaa4de44e79bac70f4"
1340513405
integrity sha512-HTUrgRJ7r4dsZKU6GjmpfRK1O76h97Z8MfS1G0FozR+oF2kG6Vfe8JE6zwrkbxigziPHinCJ+gCPjA9EaBDtRw==
1340613406

13407+
css-what@^7.0.0:
13408+
version "7.0.0"
13409+
resolved "https://registry.yarnpkg.com/css-what/-/css-what-7.0.0.tgz#5796fbebd43571d73c60ba0dd7a6e75dd0d22fe4"
13410+
integrity sha512-wD5oz5xibMOPHzy13CyGmogB3phdvcDaB5t0W/Nr5Z2O/agcB8YwOz6e2Lsp10pNDzBoDO9nVa3RGs/2BttpHQ==
13411+
1340713412
css.escape@^1.5.1:
1340813413
version "1.5.1"
1340913414
resolved "https://registry.yarnpkg.com/css.escape/-/css.escape-1.5.1.tgz#42e27d4fa04ae32f931a4b4d4191fa9cddee97cb"
@@ -14056,10 +14061,10 @@ domutils@^2.5.2, domutils@^2.8.0:
1405614061
domelementtype "^2.2.0"
1405714062
domhandler "^4.2.0"
1405814063

14059-
domutils@^3.0.1:
14060-
version "3.1.0"
14061-
resolved "https://registry.yarnpkg.com/domutils/-/domutils-3.1.0.tgz#c47f551278d3dc4b0b1ab8cbb42d751a6f0d824e"
14062-
integrity sha512-H78uMmQtI2AhgDJjWeQmHwJJ2bLPD3GMmO7Zja/ZZh84wkm+4ut+IUnUdRa8uCGX88DiVx1j6FRe1XfxEgjEZA==
14064+
domutils@^3.2.2:
14065+
version "3.2.2"
14066+
resolved "https://registry.yarnpkg.com/domutils/-/domutils-3.2.2.tgz#edbfe2b668b0c1d97c24baf0f1062b132221bc78"
14067+
integrity sha512-6kZKyUajlDuqlHKVX1w7gyslj9MPIXzIFiz/rGu35uC1wMi+kMhQwGhl4lt9unC9Vb9INnY9Z3/ZA3+FhASLaw==
1406314068
dependencies:
1406414069
dom-serializer "^2.0.0"
1406514070
domelementtype "^2.3.0"
@@ -20964,7 +20969,7 @@ npmlog@^6.0.0:
2096420969
gauge "^4.0.3"
2096520970
set-blocking "^2.0.0"
2096620971

20967-
nth-check@^2.0.1:
20972+
nth-check@^2.0.1, nth-check@^2.1.1:
2096820973
version "2.1.1"
2096920974
resolved "https://registry.yarnpkg.com/nth-check/-/nth-check-2.1.1.tgz#c9eab428effce36cd6b92c924bdb000ef1f1ed1d"
2097020975
integrity sha512-lqjrjmaOoAnWfMmBPL+XNnynZh2+swxiX3WUE0s4yEHI6m+AwrK2UZOimIRl3X/4QctVqS8AiZjFqyOGrMXb/w==
@@ -24574,10 +24579,10 @@ sass@^1.49.9:
2457424579
immutable "^4.0.0"
2457524580
source-map-js ">=0.6.2 <2.0.0"
2457624581

24577-
sax@^1.2.4, sax@^1.5.0:
24578-
version "1.5.0"
24579-
resolved "https://registry.yarnpkg.com/sax/-/sax-1.5.0.tgz#b5549b671069b7aa392df55ec7574cf411179eb8"
24580-
integrity sha512-21IYA3Q5cQf089Z6tgaUTr7lDAyzoTPx5HRtbhsME8Udispad8dC/+sziTNugOEx54ilvatQ9YCzl4KQLPcRHA==
24582+
sax@1.6.1, sax@^1.2.4:
24583+
version "1.6.1"
24584+
resolved "https://registry.yarnpkg.com/sax/-/sax-1.6.1.tgz#4c23cf608c0b693ab54b4b5888e92cfe977b9843"
24585+
integrity sha512-42tBVwLWnaQvW5zc4HbZrTuWccECCZfBi92FDuwtqxasH+JbPB3/FOKb1m222K42R4WxuxzzMsTswfzgtSu64Q==
2458124586

2458224587
sax@~1.2.4:
2458324588
version "1.2.4"
@@ -25907,17 +25912,17 @@ svelte@^4.2.8:
2590725912
periscopic "^3.1.0"
2590825913

2590925914
svgo@^4.0.1:
25910-
version "4.0.2"
25911-
resolved "https://registry.yarnpkg.com/svgo/-/svgo-4.0.2.tgz#a62246f0a9d671c0314d04f3cc15f78b1bd0667f"
25912-
integrity sha512-ekx94z1rRc5LDi6oSUaeRnYhd0UOJxdtQCL2rF8xpWxD3TPAsISWOrxezqGovqS38GRZOdpDfvQe3ts6F7nsng==
25915+
version "4.1.0"
25916+
resolved "https://registry.yarnpkg.com/svgo/-/svgo-4.1.0.tgz#c977eb69640ef232a5e8236a5a327ed8c9d52853"
25917+
integrity sha512-bkxnTg1kSU0guhIBmibA6UUhrQmPVA1XsQLN+ylCd+UWzbnLkySOcXpyk1mrl05f+pcaCx2eHb+sp6BgMZWX+Q==
2591325918
dependencies:
2591425919
commander "^11.1.0"
25915-
css-select "^5.1.0"
25920+
css-select "^6.0.0"
2591625921
css-tree "^3.0.1"
25917-
css-what "^6.1.0"
25922+
css-what "^7.0.0"
2591825923
csso "^5.0.5"
2591925924
picocolors "^1.1.1"
25920-
sax "^1.5.0"
25925+
sax "1.6.1"
2592125926

2592225927
swr@^2.2.5:
2592325928
version "2.2.5"

0 commit comments

Comments
 (0)