Skip to content

Backport/v2 security fixes - #8309

Merged
bdbch merged 6 commits into
maintenance/v2from
backport/v2-security-fixes
Sep 4, 2026
Merged

bdbch merged 6 commits into
maintenance/v2from
backport/v2-security-fixes

Conversation

@bdbch

@bdbch bdbch commented Sep 4, 2026

Copy link
Copy Markdown
Member

This PR backports two security patches back to v2

@changeset-bot

changeset-bot Bot commented Sep 4, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 1c14b18

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 68 packages
Name Type
@tiptap/pm Patch
@tiptap/core Patch
@tiptap/extension-blockquote Patch
@tiptap/extension-bold Patch
@tiptap/extension-bubble-menu Patch
@tiptap/extension-bullet-list Patch
@tiptap/extension-character-count Patch
@tiptap/extension-code-block-lowlight Patch
@tiptap/extension-code-block Patch
@tiptap/extension-code Patch
@tiptap/extension-collaboration-cursor Patch
@tiptap/extension-collaboration Patch
@tiptap/extension-color Patch
@tiptap/extension-details-content Patch
@tiptap/extension-details-summary Patch
@tiptap/extension-details Patch
@tiptap/extension-document Patch
@tiptap/extension-drag-handle-react Patch
@tiptap/extension-drag-handle-vue-2 Patch
@tiptap/extension-drag-handle-vue-3 Patch
@tiptap/extension-drag-handle Patch
@tiptap/extension-dropcursor Patch
@tiptap/extension-emoji Patch
@tiptap/extension-file-handler Patch
@tiptap/extension-floating-menu Patch
@tiptap/extension-focus Patch
@tiptap/extension-font-family Patch
@tiptap/extension-gapcursor Patch
@tiptap/extension-hard-break Patch
@tiptap/extension-heading Patch
@tiptap/extension-highlight Patch
@tiptap/extension-history Patch
@tiptap/extension-horizontal-rule Patch
@tiptap/extension-image Patch
@tiptap/extension-invisible-characters Patch
@tiptap/extension-italic Patch
@tiptap/extension-link Patch
@tiptap/extension-list-item Patch
@tiptap/extension-list-keymap Patch
@tiptap/extension-mathematics Patch
@tiptap/extension-mention Patch
@tiptap/extension-node-range Patch
@tiptap/extension-ordered-list Patch
@tiptap/extension-paragraph Patch
@tiptap/extension-placeholder Patch
@tiptap/extension-strike Patch
@tiptap/extension-subscript Patch
@tiptap/extension-superscript Patch
@tiptap/extension-table-cell Patch
@tiptap/extension-table-header Patch
@tiptap/extension-table-of-contents Patch
@tiptap/extension-table-row Patch
@tiptap/extension-table Patch
@tiptap/extension-task-item Patch
@tiptap/extension-task-list Patch
@tiptap/extension-text-align Patch
@tiptap/extension-text-style Patch
@tiptap/extension-text Patch
@tiptap/extension-typography Patch
@tiptap/extension-underline Patch
@tiptap/extension-unique-id Patch
@tiptap/extension-youtube Patch
@tiptap/html Patch
@tiptap/react Patch
@tiptap/starter-kit Patch
@tiptap/suggestion Patch
@tiptap/vue-2 Patch
@tiptap/vue-3 Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@netlify

netlify Bot commented Sep 4, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for tiptap-embed ready!

Name Link
🔨 Latest commit 1c14b18
🔍 Latest deploy log https://app.netlify.com/projects/tiptap-embed/deploys/6a9a8cca18fe2b0008a4cbf5
😎 Deploy Preview https://deploy-preview-8309--tiptap-embed.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@coderabbitai

coderabbitai Bot commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Team

Run ID: 7cd0ebf5-6f43-45f3-8ed6-f4a537449b4b

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@bdbch
bdbch merged commit fa6abcc into maintenance/v2 Sep 4, 2026
4 of 5 checks passed
@bdbch
bdbch deleted the backport/v2-security-fixes branch September 4, 2026 09:18
acamarata added a commit to nself-org/nchat that referenced this pull request Oct 4, 2026
* fix(deps): move @tiptap/* to the patched 2.27.3 backport, add mergeAttributes prototype-pollution test

GHSA-cp6q-959q-f8rh is fixed on the v2 line by ueberdosis/tiptap#8309
(fa6abcce65, @tiptap/core 2.27.3). All @tiptap/* specs are now ^2.27.3
(the stray extension-placeholder ^3.21.0 returns to 2.x); prosemirror-view
resolves to 1.42.6. Tiptap 3 moves with the Vite cutover (D-0025).

Refs: P7-HYG-27

* style(test): apply prettier to tiptap-merge-attributes test
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants