aminghadersohi opened a new pull request, #44960:
URL: https://github.com/apache/superset/pull/44960

   ### SUMMARY
   
   Restore DOMPurify 3.4.16 in the frontend lockfile and raise the root 
DOMPurify override to `^3.4.16`, matching 
`packages/superset-ui-core/package.json`.
   
   The lockfile regeneration in https://github.com/apache/superset/pull/39434 
dropped the nested UI-core DOMPurify 3.4.16 entry added by 
https://github.com/apache/superset/pull/44830, leaving the hoisted 3.4.15 
resolution below UI core's declared range. Regenerating with the repository's 
Node 24.16.0 / npm 11.13.0 produces one hoisted 3.4.16 entry with no unrelated 
lockfile changes.
   
   DOMPurify 3.4.16 is the patched release for the low-severity upstream 
advisories https://github.com/advisories/GHSA-p98j-92pf-mc4p and 
https://github.com/advisories/GHSA-6688-9rhm-gjv2. This restores the dependency 
bump; it does not assert that Superset's Tooltip usage meets the advisories' 
exploit preconditions.
   
   ### BEFORE/AFTER SCREENSHOTS OR ANIMATED GIF
   
   Not applicable; dependency-only change.
   
   ### TESTING INSTRUCTIONS
   
   With Node 24.16.0 (see `superset-frontend/.nvmrc`) and npm 11.13.0:
   
   ```bash
   npm --prefix superset-frontend ci
   npm ls dompurify --prefix superset-frontend
   npm --prefix superset-frontend run test -- --max-workers=2 --runTestsByPath 
packages/superset-ui-core/src/components/AsyncAceEditor/Tooltip.test.tsx 
packages/superset-ui-core/src/components/AsyncAceEditor/AsyncAceEditor.test.tsx
   git add superset-frontend/package.json superset-frontend/package-lock.json
   pre-commit run
   ```
   
   Expect a successful clean install, only DOMPurify 3.4.16 in the dependency 
tree, passing Tooltip / AsyncAceEditor tests, and passing applicable pre-commit 
hooks.
   
   ### ADDITIONAL INFORMATION
   
   - [ ] Has associated issue:
   - [ ] Required feature flags:
   - [ ] Changes UI
   - [ ] Includes DB Migration (follow approval process in 
[SIP-59](https://github.com/apache/superset/issues/13351))
     - [ ] Migration is atomic, supports rollback & is backwards-compatible
     - [ ] Confirm DB migration upgrade and downgrade tested
     - [ ] Runtime estimates and downtime expectations provided
   - [ ] Introduces new feature or API
   - [ ] Removes existing feature or API
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to