Skip to content

fix(deps): patch DOMPurify and fast-uri security advisories - #4358

Merged
martinothamar merged 1 commit into
Altinn:mainfrom
martinothamar-agent:fix/security-dompurify-fast-uri
Oct 2, 2026
Merged

martinothamar merged 1 commit into
Altinn:mainfrom
martinothamar-agent:fix/security-dompurify-fast-uri

Conversation

@martinothamar-agent

@martinothamar-agent martinothamar-agent commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Description

Patch DOMPurify 3.4.13 → 3.4.16 and fast-uri 3.1.7 → 3.1.8, and deduplicate Ajv within its existing major versions. Direct runtime Ajv remains 8.20.0.

Risk assessment

Both libraries run in production, but no exploitable path for either advisory was identified: DOMPurify sanitizes strings without IN_PLACE or node-removing hooks; fast-uri resolves schema references through Ajv and is not used for host access checks.

No regression was found in completed tests. Remaining compatibility risks are changed sanitization of unusual markup and changed resolution of unusual schema $id/$ref values. The backport upgrades production fast-uri from 3.0.6 → 3.1.8, so it includes more parsing changes than the diff against main.

Recommend a routine backport. Before publishing, test rendering, form loading, validation, and submission with the actual backported bundle in representative apps. A stable release updates the shared /4/ and /4.34/ CDN paths. If a regression occurs, the existing rollback workflow can restore the previous stable bundle; already-open sessions require a reload.

Related Issue(s)

Dependabot alerts #395 — DOMPurify and #382 — fast-uri.

Verification/QA

  • 414 targeted local tests and advisory-specific assertions passed.
  • Immutable install, type checks, lint, formatting, production build, and targeted deduplication check passed.
  • Full unit-test CI passed.
  • External Cypress is pending; backported-bundle browser testing remains to be done. External-app schema collection was unavailable locally.
  • No documentation or Studio changes required; kind/dependencies and backport labels applied.

@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 31 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: e46955ce-c095-4612-95dc-7b803416ea60

📥 Commits

Reviewing files that changed from the base of the PR and between 0252308 and 1103467.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (1)
  • package.json
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@martinothamar martinothamar added kind/dependencies Pull requests that update a dependency file dependencies Pull requests that update a dependency file backport This PR should be cherry-picked onto older release branches labels Oct 1, 2026
@martinothamar
martinothamar merged commit 86cfb07 into Altinn:main Oct 2, 2026
8 of 11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport This PR should be cherry-picked onto older release branches dependencies Pull requests that update a dependency file kind/dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants