Visitar URL original
Bump the npm_and_yarn group across 7 directories with 4 updates by dependabot[bot] · Pull Request #22780 · github/codeql · GitHub
Skip to content

Bump the npm_and_yarn group across 7 directories with 4 updates - #22780

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/javascript/ql/test/library-tests/HtmlSanitizers/npm_and_yarn-d1f7f2126b
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/javascript/ql/test/library-tests/HtmlSanitizers/npm_and_yarn-d1f7f2126b

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm_and_yarn group with 2 updates in the /javascript/ql/test/library-tests/HtmlSanitizers directory: sanitize-html and validator.
Bumps the npm_and_yarn group with 1 update in the /javascript/ql/test/library-tests/frameworks/Next directory: next.
Bumps the npm_and_yarn group with 1 update in the /javascript/ql/test/query-tests/Security/CWE-079/DomBasedXss directory: next.
Bumps the npm_and_yarn group with 1 update in the /javascript/ql/test/query-tests/Security/CWE-079/ReflectedXss directory: next.
Bumps the npm_and_yarn group with 1 update in the /javascript/ql/test/query-tests/Security/CWE-915/PrototypePollutingMergeCall/src-non-vulnerable-lodash directory: lodash.
Bumps the npm_and_yarn group with 1 update in the /javascript/ql/test/query-tests/Security/CWE-915/PrototypePollutingMergeCall/src-vulnerable-lodash directory: lodash.
Bumps the npm_and_yarn group with 1 update in the /javascript/ql/test/query-tests/Security/CWE-918/Request directory: next.

Updates sanitize-html from 1.27.5 to 2.18.0

Changelog

Sourced from sanitize-html's changelog.

2.18.0 (2026-09-30)

Adds

  • Added a logger option: pass any console-shaped object, with debug, info, warn and error methods, and sanitize-html's own diagnostics are delivered to it rather than to the console, so an application with a logging pipeline of its own can route them. Missing methods, and no option at all, fall back to the console. Those messages also lost their decorative line breaks and warning icon, so each is now a single line of text; their wording is otherwise unchanged.

Fixes

  • allowedSchemesByTag is now applied to srcset and imagesrcset URLs. Previously the per-tag lookup used the attribute name instead of the tag name, so these attributes always fell back to the global allowedSchemes and ignored a tag-specific scheme allowlist. Thanks to spokodev for the fix.
  • Starting in version 2.17.6, sanitize-html began escaping any markup preserved inside a disallowed iframe tag, which was a change in behavior due to an upstream change in htmlparser2. This fix ensures such "fallback markup" is preserved without escaping, but also fully sanitized according to the same rules as the original input. Thanks to sumitjhacodes for the fix.

Security

  • When meta was allowed together with its http-equiv and content attributes, the destination URL of a <meta http-equiv="refresh" content="0;url=..."> was never checked against allowedSchemes, because it is embedded in content rather than being an attribute of its own. So javascript:, data: and other disallowed destinations passed through. The refresh URL is now extracted the way browsers do it, allowing for the different spellings, separators, quoting and letter case of url=, and checked against allowedSchemes (or allowedSchemesByTag.meta). If it is rejected, or the content cannot be parsed as a refresh, the content attribute is removed. content on other meta elements is unchanged. The default configuration does not allow meta and was not affected (CWE-79, CWE-601, GHSA-cv27-6wvh-8x7j).

    Thanks to adrbogacz for reporting the vulnerability.

  • When noscript is listed in nonTextTags, the discarded region could end too early. Browsers with scripting enabled treat <noscript> content as raw text up to the first </noscript>, but the underlying parser treats it as markup, so an end tag for an enclosing element inside <noscript> closed it implicitly and the rest of its content was emitted as ordinary sanitized markup. The discard region now continues until the point where a browser would end the <noscript> element, while implied closes of other nonTextTags such as <option> behave as before (CWE-79, CWE-436, GHSA-x3q4-9hxx-gx8m).

    Thanks to joaquiniglesiaslug for reporting the vulnerability.

  • The check that drops SVG animation elements (animate, animateColor, animateMotion, animateTransform, set) when they retarget a URL attribute such as href compared the full tag name, so a namespace-prefixed spelling like svg:animate was not recognized when such tags were allowed (for example with allowedTags: false). In XML serializations such as XHTML or standalone SVG, the prefixed element is a real animation element and could retarget a link to a javascript: URL after sanitization. The element and attributeName are now matched by their local names, ignoring any prefix (CWE-79, CWE-184, GHSA-374f-7chj-9948).

    Thanks to Kai Aizen (SnailSploit) for reporting the vulnerability.

2.17.7 (2026-08-13)

Security

  • Fixed an XSS / URL scheme policy bypass affecting configurations that allow the SVG animation elements (animate, animateColor, animateMotion, animateTransform or set) together with attributeName and one of the animation value attributes. The default configuration was not affected, as these elements are not in the default allowedTags. apostrophecms was not affected. Thanks to koyokr for responsibly disclosing the vulnerability (GHSA-g8qq-57p8-ggw5).

2.17.6 (2026-07-10)

Fixes

  • Allow transformTags to emit text when textFilter is set, even if the tag is initially empty. This is consistent with the documentation. Thanks to spokodev for the fix.

Security

  • Fixed an XSS/allowlist bypass in which the contents of a raw-text element (textarea or xmp) nested inside an svg or math root were re-emitted without HTML-escaping. sanitize-html treated that content as inert raw text because htmlparser2 10.x classified raw-text elements by tag name and ignored the namespace, but a real HTML5 parser treats textarea/xmp as ordinary foreign elements inside SVG/MathML and re-parses their contents as live markup. As a result, markup and event-handler attributes that the allowlist never permitted (for example <svg><textarea><img src=x onerror=alert(1)>) could survive sanitization and execute in the browser. This is now fixed on two fronts: htmlparser2 was upgraded to 12.x, which is namespace-aware and parses textarea/xmp inside SVG/MathML as ordinary elements, so their non-allowlisted children (such as the injected img) are dropped by the allowlist instead of being preserved as raw text; and any raw-text content sanitize-html still emits for these tags (at HTML integration points such as foreignObject/mtext, or outside foreign content) is always HTML-escaped. The default configuration is not affected; the precondition is an allowedTags that includes svg or math together with textarea or xmp. Thanks to khoadb175 for responsibly disclosing the vulnerability.
  • Fixed a mutation-XSS / allowedTags bypass affecting configurations that allow the textarea or xmp raw-text tags. htmlparser2 10.x did not recognize an end tag with a trailing solidus (e.g. </textarea/>) as closing the element, so it kept the following markup as raw text, but a spec-compliant browser treats </textarea/> as a valid close and parses that markup as a live element. Because raw-text content was re-emitted without escaping, a payload such as <textarea></textarea/><img src=x onerror=...> could smuggle non-allowlisted, executable markup through the sanitizer. The default configuration was not affected. This is now defended at two layers: htmlparser2 was upgraded to 12.x, whose tokenizer closes these end tags correctly, and the raw text sanitize-html emits for these tags is always escaped so no < can reopen a tag when the output is re-parsed (textarea, an RCDATA element whose entities htmlparser2 decodes, is escaped like normal text, while xmp, a raw-text element, has only its angle brackets escaped to avoid double-encoding already-encoded entities). Because htmlparser2 is ESM-only from version 11 onward, sanitize-html now requires Node.js >=22.12.0 (the first 22.x release in which require() of an ES module is available unflagged). Thanks to bibu123456 for reporting the vulnerability and Kayiz-PT for coordinating the disclosure (GHSA-jxwj-j7wr-gfrw).

2.17.5 (2026-06-10)

Security

... (truncated)

Commits

Updates validator from 10.11.0 to 13.15.35

Release notes

Sourced from validator's releases.

13.15.35

Fixes, New Locales and Enhancements

New Contributors

Full Changelog: validatorjs/validator.js@13.15.26...13.15.35

13.15.26

Fixes, New Locales and Enhancements

New Contributors

Full Changelog: validatorjs/validator.js@13.15.23...13.15.26

13.15.23

Fixes, New Locales and Enhancements

... (truncated)

Changelog

Sourced from validator's changelog.

13.15.35

Fixes, New Locales and Enhancements

13.15.26

Fixes, New Locales and Enhancements

13.15.23

Fixes, New Locales and Enhancements

13.15.22

Fixes, New Locales and Enhancements

13.15.20

Fixes, New Locales and Enhancements

... (truncated)

Commits
  • 7a80797 maintenance: 2604 release (#2695)
  • 941db7f fix(isSlug): restrict allowed characters to valid slug charset (#2693)
  • 2758f70 chore: fix typo in comment (#2591)
  • fcfbff5 feat(isJson): allow any valid JSON value to pass (#2690)
  • f06caee refactor: replace if-then-else flow by a single return statement (#2592)
  • 9fa1e3a feat(isPostalCode): Add postal code for Monaco (#2682)
  • b1aea75 feat(isMobilePhone): add Djibouti (fr-DJ) mobile phone validation (#2676)
  • f715cdd fix(isPassportNumber): improve MX locale (#2643)
  • e8c6914 fix(isTaxID): add formatted CPF support and additional test cases for pt-BR l...
  • 90b0a9a fix(isTaxID): improve pt-BR locale by adding support for alphanumeric CNPJ ...
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for validator since your current version.


Updates next from 10.2.3 to 16.4.0

Release notes

Sourced from next's releases.

v16.4.0

Check out the 16.4 announcement post to get an overview of the changes.

Core Changes

  • Show compiler plugin warning in more situations: #75682
  • fix(scripts): correct typo in rm.mjs error message: #87015
  • docs: improve clarity and punctuation in README: #86096
  • Fix debug build paths Pages Router support entries: #93529
  • bundle-analyzer: record historical snapshots on each analyze run: #93520
  • fix: detect proxy.ts correctly with compound pageExtensions: #93246
  • feat(turbopack): support false values for resolveAlias config: #93331

Misc Changes

  • docs: correction to dynamicParams migration: #96624
  • docs: proxy event argument: #96435
  • docs: remove experimental note from runtime prefetching: #96615
  • Preserve per-segment prefetching after dynamic navigation: #96583
  • Rename static generation stream option to waitForAllReady: #96564
  • Remove obsolete static generation plumbing: #96563
  • [turbopack] Drop dead writes to exports: #96381
  • [turbopack] Ignore writes to exports after a module.exports = {} writes: #96380
  • [turbopack] Add test for sideEffects with optimizePackageImports: #96549
  • [turbopack] Strip leading BOM before parsing CSS: #96678
  • Upgrade React from cbb046ab-20260731 to 7dfc7ccd-20260803: #96550
  • docs: use relative doc links in instant-navigation error pages: #96672
  • Turbopack: terminate failed plugin worker threads: #96592
  • Fix HTML-limited bot matching in prerender bypass rules: #96584
  • [ci] Fix create_release_branch for new repo permissions: #96641
  • test: skip action module instance deploy test: #96629
  • docs: quote the dynamicParams build error in a blockquote: #96633
  • [react-sync] Open pull requests as the bot that authors the commits: #96682
  • [Bench] Fixes for pure Fizz bench: #96771
  • Derive foreground cache revalidation from the consumer: #96731
  • Fix race when navigating Back before hydration: #96252
  • docs: present each Skill as steps in the AI agents guide: #96751
  • Reuse completed cache entries for the rest of a request: #96727
  • Upgrade React from 7dfc7ccd-20260803 to 11eddecd-20260805: #96735
  • Remove WorkStore execution mode: #96674
  • Remove cache revalidation execution mode reads: #96670
  • Separate App Route render and prerender pipelines: #96662
  • Remove App Page execution mode reads: #96660
  • test: fix missing await in css-chunking test: #96725
  • docs (Skills): stop assuming app/ at the root and port 3000: #96696
  • Implement next/font BeforeResolvePlugins as ImportMappingReplacement: #95808
  • Use Tailwind Turbopack loader in create-next-app: #96606
  • docs: instant navigation quick start with an adoption prompt: #96663
  • Separate App Page render and prerender pipelines: #96659
  • Move App Router execution intent to entrypoints: #96640

... (truncated)

Commits
  • e273d5b v16.4.0
  • fdf41d6 [ai-upgrade] discover upgrade models and reasoning efforts from agent CLIs (#...
  • c3e76ad v16.4.0-canary.63
  • 47c6cc8 Document next analyze export in the package bundling guide (#99735)
  • 5b10604 Revert stabilization of forbidden() and unauthorized() (#99734)
  • f3a6f97 Preserve configured output directories during static export (#99507)
  • b22e5a2 Rename skill to next-bundle-optimizer and document its usage (#99731)
  • 74dc549 [turbo-tasks-backend] Clean up task state before publishing execution complet...
  • ccf8c15 v16.4.0-canary.62
  • b8c7c7f Improve static route error guidance (#99724)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for next since your current version.


Updates next from 10.2.3 to 16.4.0

Release notes

Sourced from next's releases.

v16.4.0

Check out the 16.4 announcement post to get an overview of the changes.

Core Changes

  • Show compiler plugin warning in more situations: #75682
  • fix(scripts): correct typo in rm.mjs error message: #87015
  • docs: improve clarity and punctuation in README: #86096
  • Fix debug build paths Pages Router support entries: #93529
  • bundle-analyzer: record historical snapshots on each analyze run: #93520
  • fix: detect proxy.ts correctly with compound pageExtensions: #93246
  • feat(turbopack): support false values for resolveAlias config: #93331

Misc Changes

  • docs: correction to dynamicParams migration: #96624
  • docs: proxy event argument: #96435
  • docs: remove experimental note from runtime prefetching: #96615
  • Preserve per-segment prefetching after dynamic navigation: #96583
  • Rename static generation stream option to waitForAllReady: #96564
  • Remove obsolete static generation plumbing: #96563
  • [turbopack] Drop dead writes to exports: #96381
  • [turbopack] Ignore writes to exports after a module.exports = {} writes: #96380
  • [turbopack] Add test for sideEffects with optimizePackageImports: #96549
  • [turbopack] Strip leading BOM before parsing CSS: #96678
  • Upgrade React from cbb046ab-20260731 to 7dfc7ccd-20260803: #96550
  • docs: use relative doc links in instant-navigation error pages: #96672
  • Turbopack: terminate failed plugin worker threads: #96592
  • Fix HTML-limited bot matching in prerender bypass rules: #96584
  • [ci] Fix create_release_branch for new repo permissions: #96641
  • test: skip action module instance deploy test: #96629
  • docs: quote the dynamicParams build error in a blockquote: #96633
  • [react-sync] Open pull requests as the bot that authors the commits: #96682
  • [Bench] Fixes for pure Fizz bench: #96771
  • Derive foreground cache revalidation from the consumer: #96731
  • Fix race when navigating Back before hydration: #96252
  • docs: present each Skill as steps in the AI agents guide: #96751
  • Reuse completed cache entries for the rest of a request: #96727
  • Upgrade React from 7dfc7ccd-20260803 to 11eddecd-20260805: #96735
  • Remove WorkStore execution mode: #96674
  • Remove cache revalidation execution mode reads: #96670
  • Separate App Route render and prerender pipelines: #96662
  • Remove App Page execution mode reads: #96660
  • test: fix missing await in css-chunking test: #96725
  • docs (Skills): stop assuming app/ at the root and port 3000: #96696
  • Implement next/font BeforeResolvePlugins as ImportMappingReplacement: #95808
  • Use Tailwind Turbopack loader in create-next-app: #96606
  • docs: instant navigation quick start with an adoption prompt: #96663
  • Separate App Page render and prerender pipelines: #96659
  • Move App Router execution intent to entrypoints: #96640

... (truncated)

Commits
  • e273d5b v16.4.0
  • fdf41d6 [ai-upgrade] discover upgrade models and reasoning efforts from agent CLIs (#...
  • c3e76ad v16.4.0-canary.63
  • 47c6cc8 Document next analyze export in the package bundling guide (#99735)
  • 5b10604 Revert stabilization of forbidden() and unauthorized() (#99734)
  • f3a6f97 Preserve configured output directories during static export (#99507)
  • b22e5a2 Rename skill to next-bundle-optimizer and document its usage (#99731)
  • 74dc549 [turbo-tasks-backend] Clean up task state before publishing execution complet...
  • ccf8c15 v16.4.0-canary.62
  • b8c7c7f Improve static route error guidance (#99724)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for next since your current version.


Updates next from 10.2.3 to 16.4.0

Release notes

Sourced from next's releases.

v16.4.0

Check out the 16.4 announcement post to get an overview of the changes.

Core Changes

  • Show compiler plugin warning in more situations: #75682
  • fix(scripts): correct typo in rm.mjs error message: #87015
  • docs: improve clarity and punctuation in README: #86096
  • Fix debug build paths Pages Router support entries: #93529
  • bundle-analyzer: record historical snapshots on each analyze run: #93520
  • fix: detect proxy.ts correctly with compound pageExtensions: #93246
  • feat(turbopack): support false values for resolveAlias config: #93331

Misc Changes

  • docs: correction to dynamicParams migration: #96624
  • docs: proxy event argument: #96435
  • docs: remove experimental note from runtime prefetching: #96615
  • Preserve per-segment prefetching after dynamic navigation: #96583
  • Rename static generation stream option to waitForAllReady: #96564
  • Remove obsolete static generation plumbing: #96563
  • [turbopack] Drop dead writes to exports: #96381
  • [turbopack] Ignore writes to exports after a module.exports = {} writes: #96380
  • [turbopack] Add test for sideEffects with optimizePackageImports: #96549
  • [turbopack] Strip leading BOM before parsing CSS: #96678
  • Upgrade React from cbb046ab-20260731 to 7dfc7ccd-20260803: #96550
  • docs: use relative doc links in instant-navigation error pages: #96672
  • Turbopack: terminate failed plugin worker threads: #96592
  • Fix HTML-limited bot matching in prerender bypass rules: #96584
  • [ci] Fix create_release_branch for new repo permissions: #96641
  • test: skip action module instance deploy test: #96629
  • docs: quote the dynamicParams build error in a blockquote: #96633
  • [react-sync] Open pull requests as the bot that authors the commits: #96682
  • [Bench] Fixes for pure Fizz bench: #96771
  • Derive foreground cache revalidation from the consumer: #96731
  • Fix race when navigating Back before hydration: #96252
  • docs: present each Skill as steps in the AI agents guide: #96751
  • Reuse completed cache entries for the rest of a request: #96727
  • Upgrade React from 7dfc7ccd-20260803 to 11eddecd-20260805: #96735
  • Remove WorkStore execution mode: #96674
  • Remove cache revalidation execution mode reads: #96670
  • Separate App Route render and prerender pipelines: #96662
  • Remove App Page execution mode reads: #96660
  • test: fix missing await in css-chunking test: #96725
  • docs (Skills): stop assuming app/ at the root and port 3000: #96696
  • Implement next/font BeforeResolvePlugins as ImportMappingReplacement: #95808
  • Use Tailwind Turbopack loader in create-next-app: #96606
  • docs: instant navigation quick start with an adoption prompt: #96663
  • Separate App Page render and prerender pipelines: #96659
  • Move App Router execution intent to entrypoints: #96640

... (truncated)

Commits
  • e273d5b v16.4.0
  • fdf41d6 [ai-upgrade] discover upgrade models and reasoning efforts from agent CLIs (#...
  • c3e76ad v16.4.0-canary.63
  • 47c6cc8 Document next analyze export in the package bundling guide (#99735)
  • 5b10604 Revert stabilization of forbidden() and unauthorized() (#99734)
  • f3a6f97 Preserve configured output directories during static export (#99507)
  • b22e5a2 Rename skill to next-bundle-optimizer and document its usage (#99731)
  • 74dc549 [turbo-tasks-backend] Clean up task state before publishing execution complet...
  • ccf8c15 v16.4.0-canary.62
  • b8c7c7f Improve static route error guidance (#99724)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for next since your current version.


Updates lodash from 4.17.12 to 4.18.1

Release notes

Sourced from lodash's releases.

4.18.1

Bugs

Fixes a ReferenceError issue in lodash lodash-es lodash-amd and lodash.template when using the template and fromPairs functions from the modular builds. See lodash/lodash#6167

These defects were related to how lodash distributions are built from the main branch using https://github.com/lodash-archive/lodash-cli. When internal dependencies change inside lodash functions, equivalent updates need to be made to a mapping in the lodash-cli. (hey, it was ahead of its time once upon a time!). We know this, but we missed it in the last release. It's the kind of thing that passes in CI, but fails bc the build is not the same thing you tested.

There is no diff on main for this, but you can see the diffs for each of the npm packages on their respective branches:

4.18.0

v4.18.0

Full Changelog: lodash/lodash@4.17.23...4.18.0

Security

_.unset / _.omit: Fixed prototype pollution via constructor/prototype path traversal (GHSA-f23m-r3pf-42rh, fe8d32e). Previously, array-wrapped path segments and primitive roots could bypass the existing guards, allowing deletion of properties from built-in prototypes. Now constructor and prototype are blocked unconditionally as non-terminal path keys, matching baseSet. Calls that previously returned true and deleted the property now return false and leave the target untouched.

_.template: Fixed code injection via imports keys (GHSA-r5fr-rjxr-66jc, CVE-2026-4800, 879aaa9). Fixes an incomplete patch for CVE-2021-23337. The variable option was validated against reForbiddenIdentifierChars but importsKeys was left unguarded, allowing code injection via the same Function() constructor sink. imports keys containing forbidden identifier characters now throw "Invalid imports option passed into _.template".

Docs

  • Add security notice for _.template in threat model and API docs (#6099)
  • Document lower > upper behavior in _.random (#6115)
  • Fix quotes in _.compact jsdoc (#6090)

lodash.* modular packages

Diff

We have also regenerated and published a select number of the lodash.* modular packages.

These modular packages had fallen out of sync significantly from the minor/patch updates to lodash. Specifically, we have brought the following packages up to parity w/ the latest lodash release because they have had CVEs on them in the past:

Commits
  • cb0b9b9 release(patch): bump main to 4.18.1 (#6177)
  • 75535f5 chore: prune stale advisory refs (#6170)
  • 62e91bc docs: remove n_ Node.js < 6 REPL note from README (#6165)
  • 59be2de release(minor): bump to 4.18.0 (#6161)
  • af63457 fix: broken tests for _.template 879aaa9
  • 1073a76 fix: linting issues
  • 879aaa9 fix: validate imports keys in _.template
  • fe8d32e fix: block prototype pollution in baseUnset via constructor/prototype traversal
  • 18ba0a3 refactor(fromPairs): use baseAssignValue for consistent assignment (#6153)
  • b819080 ci: add dist sync validation workflow (#6137)
  • Additional commits viewable in compare view

Updates lodash from 4.17.4 to 4.18.1

Release notes

Sourced from lodash's releases.

4.18.1

Bugs

Fixes a ReferenceError issue in lodash lodash-es lodash-amd and lodash.template when using the template and fromPairs functions from the modular builds. See lodash/lodash#6167

These defects were related to how lodash distributions are built from the main branch using https://github.com/lodash-archive/lodash-cli. When internal dependencies change inside lodash functions, equivalent updates need to be made to a mapping in the lodash-cli. (hey, it was ahead of its time once upon a time!). We know this, but we missed it in the last release. It's the kind of thing that passes in CI, but fails bc the build is not the same thing you tested.

There is no diff on main for this, but you can see the diffs for each of the npm packages on their respective branches:

4.18.0

v4.18.0

Full Changelog: lodash/lodash@4.17.23...4.18.0

Security

_.unset / _.omit: Fixed prototype pollution via constructor/prototype path traversal (GHSA-f23m-r3pf-42rh, fe8d32e). Previously, array-wrapped path segments and primitive roots could bypass the existing guards, allowing deletion of properties from built-in prototypes. Now constructor and prototype are blocked unconditionally as non-terminal path keys, matching baseSet. Calls that previously returned true and deleted the property now return false and leave the target untouched.

_.template: Fixed code injection via imports keys (GHSA-r5fr-rjxr-66jc, CVE-2026-4800, 879aaa9). Fixes an incomplete patch for CVE-2021-23337. The variable option was validated against reForbiddenIdentifierChars but importsKeys was left unguarded, allowing code injection via the same Function() constructor sink. imports keys containing forbidden identifier characters now throw "Invalid imports option passed into _.template".

Docs

  • Add security notice for _.template in threat model and API docs (#6099)
  • Document lower > upper behavior in _.random (#6115)
  • Fix quotes in _.compact jsdoc (#6090)

lodash.* modular packages

Diff

We ...

Description has been truncated

Bumps the npm_and_yarn group with 2 updates in the /javascript/ql/test/library-tests/HtmlSanitizers directory: [sanitize-html](https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html) and [validator](https://github.com/validatorjs/validator.js).
Bumps the npm_and_yarn group with 1 update in the /javascript/ql/test/library-tests/frameworks/Next directory: [next](https://github.com/vercel/next.js).
Bumps the npm_and_yarn group with 1 update in the /javascript/ql/test/query-tests/Security/CWE-079/DomBasedXss directory: [next](https://github.com/vercel/next.js).
Bumps the npm_and_yarn group with 1 update in the /javascript/ql/test/query-tests/Security/CWE-079/ReflectedXss directory: [next](https://github.com/vercel/next.js).
Bumps the npm_and_yarn group with 1 update in the /javascript/ql/test/query-tests/Security/CWE-915/PrototypePollutingMergeCall/src-non-vulnerable-lodash directory: [lodash](https://github.com/lodash/lodash).
Bumps the npm_and_yarn group with 1 update in the /javascript/ql/test/query-tests/Security/CWE-915/PrototypePollutingMergeCall/src-vulnerable-lodash directory: [lodash](https://github.com/lodash/lodash).
Bumps the npm_and_yarn group with 1 update in the /javascript/ql/test/query-tests/Security/CWE-918/Request directory: [next](https://github.com/vercel/next.js).


Updates `sanitize-html` from 1.27.5 to 2.18.0
- [Changelog](https://github.com/apostrophecms/apostrophe/blob/main/packages/sanitize-html/CHANGELOG.md)
- [Commits](https://github.com/apostrophecms/apostrophe/commits/sanitize-html@2.18.0/packages/sanitize-html)

Updates `validator` from 10.11.0 to 13.15.35
- [Release notes](https://github.com/validatorjs/validator.js/releases)
- [Changelog](https://github.com/validatorjs/validator.js/blob/master/CHANGELOG.md)
- [Commits](validatorjs/validator.js@10.11.0...13.15.35)

Updates `next` from 10.2.3 to 16.4.0
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v10.2.3...v16.4.0)

Updates `next` from 10.2.3 to 16.4.0
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v10.2.3...v16.4.0)

Updates `next` from 10.2.3 to 16.4.0
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v10.2.3...v16.4.0)

Updates `lodash` from 4.17.12 to 4.18.1
- [Release notes](https://github.com/lodash/lodash/releases)
- [Commits](lodash/lodash@4.17.12...4.18.1)

Updates `lodash` from 4.17.4 to 4.18.1
- [Release notes](https://github.com/lodash/lodash/releases)
- [Commits](lodash/lodash@4.17.12...4.18.1)

Updates `next` from 15.1.7 to 15.5.27
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v10.2.3...v16.4.0)

---
updated-dependencies:
- dependency-name: sanitize-html
  dependency-version: 2.18.0
  dependency-type: direct:production
  dependency-group: npm_and_yarn
- dependency-name: validator
  dependency-version: 13.15.35
  dependency-type: direct:production
  dependency-group: npm_and_yarn
- dependency-name: next
  dependency-version: 16.4.0
  dependency-type: direct:production
  dependency-group: npm_and_yarn
- dependency-name: next
  dependency-version: 16.4.0
  dependency-type: direct:production
  dependency-group: npm_and_yarn
- dependency-name: next
  dependency-version: 16.4.0
  dependency-type: direct:production
  dependency-group: npm_and_yarn
- dependency-name: lodash
  dependency-version: 4.18.1
  dependency-type: direct:production
  dependency-group: npm_and_yarn
- dependency-name: lodash
  dependency-version: 4.18.1
  dependency-type: direct:production
  dependency-group: npm_and_yarn
- dependency-name: next
  dependency-version: 15.5.27
  dependency-type: direct:production
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 8, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner October 8, 2026 08:31
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 8, 2026
@github-actions github-actions Bot added the JS label Oct 8, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code JS

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants