postmanlabs / postman-collection

Javascript module that allows a developer to work with Postman Collections

Home Page:https://www.postmanlabs.com/postman-collection/

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Can we bump sanitize-html dependency to address this CVE?

gone-skiing opened this issue · comments

I am happy to spin up a PR...

@codenirvana here is a PR to bump the dependency if your team has a minute...
#1183

Fixed in v4.

@codenirvana: could you also create a patch for v3?
Not everyone will like to update to a new major version for a security fix.

@delixfe Sure but can you also check the changelog to verify the breaking changes?

@codenirvana Actually, I think many of us would prefer not to have to check those. That was the reason I have asked :).
Now I did read them and I won't be affected by the breaking changes so I can easily upgrade to v4.