Backport/v2 security fixes - #8309
Conversation
Co-authored-by: Dominik Biedebach <6538827+bdbch@users.noreply.github.com>
🦋 Changeset detectedLatest commit: 1c14b18 The changes in this PR will be included in the next version bump. This PR includes changesets to release 68 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
✅ Deploy Preview for tiptap-embed ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Team Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
* fix(deps): move @tiptap/* to the patched 2.27.3 backport, add mergeAttributes prototype-pollution test GHSA-cp6q-959q-f8rh is fixed on the v2 line by ueberdosis/tiptap#8309 (fa6abcce65, @tiptap/core 2.27.3). All @tiptap/* specs are now ^2.27.3 (the stray extension-placeholder ^3.21.0 returns to 2.x); prosemirror-view resolves to 1.42.6. Tiptap 3 moves with the Vite cutover (D-0025). Refs: P7-HYG-27 * style(test): apply prettier to tiptap-merge-attributes test
This PR backports two security patches back to v2