[BUMP] Update dependency happy-dom to v15 [SECURITY] #722
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^13.6.2
->^15.0.0
GitHub Vulnerability Alerts
GHSA-96g7-g7g9-jxw8
Fixes security vulnerability that allowed for server side code to be executed by a <script> tag
Impact
Consumers of the NPM package
happy-dom
Patches
The security vulnerability has been patched in v15.10.1
Workarounds
No easy workarounds to my knowledge
References
#1585
Release Notes
capricorn86/happy-dom (happy-dom)
v15.10.1
Compare Source
v15.10.0
Compare Source
v15.9.0
Compare Source
v15.8.5
Compare Source
v15.8.4
Compare Source
v15.8.3
Compare Source
v15.8.2
Compare Source
v15.8.1
Compare Source
v15.8.0
Compare Source
v15.7.4
Compare Source
👷♂️ Patch fixes
replaceWith()
,before()
andafter()
- By @BenjaminAster in task #1533v15.7.3
Compare Source
👷♂️ Patch fixes
HTMLSelectElement
- By @Cherry in task #1526v15.7.2
Compare Source
👷♂️ Patch fixes
MutationObserver
- By @capricorn86 in task #1524v15.7.1
Compare Source
👷♂️ Patch fixes
querySelector(['.class'])
) - By @capricorn86 in task #1507v15.7.0
Compare Source
v15.6.1
Compare Source
v15.6.0
Compare Source
v15.5.0
Compare Source
v15.4.3
Compare Source
👷♂️ Patch fixes
v15.4.2
Compare Source
👷♂️ Patch fixes
v15.4.1
Compare Source
👷♂️ Patch fixes
FormData.append()
when value parameter type is incorrect - By @btea in task #1484v15.4.0
Compare Source
v15.3.2
Compare Source
👷♂️ Patch fixes
HTMLInputElement.indeterminate
, so that it behaves correctly - By @malko in task #1439v15.3.1
Compare Source
v15.3.0
Compare Source
v15.2.0
Compare Source
🎨 Features
AbortSignal.any()
- By @ezzatron in task #1468v15.1.0
Compare Source
🎨 Features
EventTarget.dispatchEvent()
to better handle the event phases "none", "capture", "atTarget" and "bubbling" - By @capricorn86 in task #1332HTMLInputElement.popoverTargetElement
,HTMLInputElement.popoverTargetAction
,HTMLButtonElement.popoverTargetElement
andHTMLButtonElement.popoverTargetAction
- By @capricorn86 in task #1332HTMLElement.popover
- By @capricorn86 in task #1332PerformanceObserver
,PerformanceEntry
andPerformanceObserverEntryList
- By @capricorn86 in task #1332👷♂️ Patch fixes
NodeList[Symbol.iterator]()
withArray.prototype.values()
- By @capricorn86 in task #1332Window
is closing (e.g. usingsetTimeout()
orfetch()
) - By @capricorn86 in task #1332Window
, which makes it possible forBrowserExceptionObserver
to know whichWindow
the error originated fromEvent.composedPath()
to not return theWindow
object if the event type is "load", which is the same behaviour as the browser - By @capricorn86 in task #1332Window
objectv15.0.0
Compare Source
💣 Breaking Changes
🎨 Features
HTMLAreaElement
,HTMLBodyElement
,HTMLQuoteElement
,HTMLBRElement
,HTMLTableCaptionElement
,HTMLTableColElement
,HTMLTableColElement
,HTMLDataElement
,HTMLDataListElement
,HTMLModElement
,HTMLDetailsElement
,HTMLDivElement
,HTMLDListElement
,HTMLEmbedElement
,HTMLFieldSetElement
,HTMLHeadingElement
,HTMLHeadElement
,HTMLHRElement
,HTMLHtmlElement
,HTMLModElement
,HTMLLegendElement
,HTMLLIElement
,HTMLMapElement
,HTMLMenuElement
,HTMLMeterElement
,HTMLObjectElement
,HTMLOListElement
,HTMLOutputElement
,HTMLParagraphElement
,HTMLParamElement
,HTMLPictureElement
,HTMLPreElement
,HTMLProgressElement
,HTMLQuoteElement
,HTMLSourceElement
,HTMLSpanElement
,HTMLTableElement
,HTMLTableSectionElement
,HTMLTableSectionElement
,HTMLTitleElement
,HTMLTableRowElement
,HTMLTrackElement
,HTMLUListElement
- By @capricorn86 in task #1332HTMLCanvasElement
- By @capricorn86 in task #1332CSSStyleDeclaration
,querySelector()
,querySelectorAll()
,getElementById()
,getElementsByClassName()
,getElementsByTagName()
,getElementsByTagNameNS()
,getElementsByClassName()
- By @capricorn86 in task #1332NodeList
,HTMLCollection
,DOMTokenList
,TextTrackList
,HTMLFormElement
,HTMLSelectElement
HTMLCollection
objects returned bygetElementsByClassName()
,getElementsByTagName()
,getElementsByTagNameNS()
andgetElementsByClassName()
live - By @capricorn86 in task #1332HTMLMediaElement
- By @capricorn86 in task #1332HTMLMediaElement
interfaceMediaStream
,MediaStreamTrack
,RemotePlayback
,TextTrack
,TextTrackCue
,TextTrackCueList
,TextTrackList
,VTTCue
,VTTRegion
,CanvasCaptureMediaStream
,ImageBitmap
,OffscreenCanvas
- By @capricorn86 in task #1332IntersectionObserver
- By @capricorn86 in task #1332HTMLInputElement.list
- By @capricorn86 in task #1332ShadowRoot
(it now supportsclonable
,serializable
andslotAssignment
) - By @capricorn86 in task #1332Element.getHTML()
- By @capricorn86 in task #1332HTMLSlotElement
- By @capricorn86 in task #1332assign()
,assignedNodes()
,assignedElements()
and theslotchange
event👷♂️ Patch fixes
XMLSerializer
(used by features such asinnerHTML
) - By @capricorn86 in task #1265waitForNavigation()
would not resolve when navigating to some URLs (e.g. "javascript" or "about:blank") - By @capricorn86 in task #1332Attr.cloneNode()
would not clone internal values - By @capricorn86 in task #1332Document.title
included text data inside child elements, which it shouldn't - By @capricorn86 in task #1332Event.preventDefault()
shouldn't cancel the default behaviour if cancelable is not sent as an option inEventTarget.dispatchEvent()
- By @capricorn86 in task #1332TimeRange
toTimeRanges
- By @capricorn86 in task #1332Window.parent
andWindow.top
would not be set correctly in some scenarios - By @capricorn86 in task #1332v14.12.3
Compare Source
👷♂️ Patch fixes
v14.12.2
Compare Source
👷♂️ Patch fixes
v14.12.1
Compare Source
👷♂️ Patch fixes
preventDefault
not preventing navigation - By @amitdahan in task #1464v14.12.0
Compare Source
v14.11.4
Compare Source
v14.11.3
Compare Source
v14.11.2
Compare Source
v14.11.1
Compare Source
v14.11.0
Compare Source
🎨 Features
HTMLTimeElement
- By @r-thomson in task #1431v14.10.3
Compare Source
👷♂️ Patch fixes
v14.10.2
Compare Source
👷♂️ Patch fixes
HTMLAnchorElement
,HTMLButtonElement
,HTMLInputElement
andHTMLLabelElement
checked that click events triggering native behavior was of typePointerEvent
, but should check that they are of typeMouseEvent
- By @capricorn86 in task #1397v14.10.1
Compare Source
v14.10.0
Compare Source
🎨 Features
Document.elementFromPoint()
- By @TreyVigus in task #1400null
as Happy DOM doesn't support rendering and can't calculate an element's position based on where it is renderedv14.9.0
Compare Source
v14.8.3
Compare Source
👷♂️ Patch fixes
Element.insertBefore()
not removing comment node from previous ancestor - By @mdafanasev in task #1406v14.8.2
Compare Source
v14.8.1
Compare Source
v14.8.0
Compare Source
🎨 Features
HTMLIFrameElement.srcdoc
property - By @jeffwcx in task #1398v14.7.1
Compare Source
👷♂️ Patch fixes
v14.7.0
Compare Source
v14.6.2
Compare Source
👷♂️ Patch fixes
Storage.prototype
methods - By @capricorn86 in task #1377v14.6.1
Compare Source
👷♂️ Patch fixes
Document.createTextNode()
didn't handle conversion of non-string values to string - By @odanado in task #1380Document.createTextNode()
- By @odanado in task #1380v14.6.0
Compare Source
v14.5.2
Compare Source
v14.5.1
Compare Source
👷♂️ Patch fixes
v14.5.0
Compare Source
🎨 Features
Request.formData()
- By @tt-public in #1379v14.4.0
Compare Source
v14.3.10
Compare Source
👷♂️ Patch fixes
v14.3.9
Compare Source
👷♂️ Patch fixes
v14.3.8
Compare Source
👷♂️ Patch fixes
:is
and :where
(without argument) was not handled correctly - By @capricorn86 in task #1352v14.3.7
Compare Source
👷♂️ Patch fixes
DOMTokenList
iterable - By @silverwind in task #1342v14.3.6
Compare Source
👷♂️ Patch fixes
v14.3.5
Compare Source
v14.3.4
Compare Source
v14.3.3
Compare Source
v14.3.2
Compare Source
👷♂️ Patch fixes
v14.3.1
Compare Source
v14.3.0
Compare Source
v14.2.1
Compare Source
v14.2.0
Compare Source
🎨 Features
:is()
and:where()
- By @capricorn86 in task #1333v14.1.2
Compare Source
👷♂️ Patch fixes
Object.getOwnPropertyDescriptors(window)
to read which properties to register globally, but getters and setters are defined on the prototypeGlobalWindow
now defines the properties on the instance when it is constructedv14.1.1
Compare Source
v14.1.0
Compare Source
🎨 Features
handleDisabledFileLoadingAsSuccess
, that can be used for triggering a "load" event instead of an "error" event when file loading is disabled - By @capricorn86 in task #1334v14.0.0
Compare Source
💣 Breaking Changes
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Never, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.