-
Notifications
You must be signed in to change notification settings - Fork 9k
security: update rollup plugins and fix potential XSS in idle sample #1607
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
security: update rollup plugins and fix potential XSS in idle sample #1607
Conversation
|
Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA). View this failed invocation of the CLA check for more information. For the most up to date status, view the checks section at the bottom of the pull request. |
d25ad72 to
f254339
Compare
oliverdunk
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for the contribution. Can you merge with main and remove the package updates? I'd be happy to accept the changes to avoid innerHTML, but we have Dependabot to update packages (we are a little behind on merging those PRs which I will try to do soon).
|
Reverted the package updates and merged main as requested. Left the innerHTML fixes as is. |
|
Added the missing newline as requested. |
Hi, I've updated this PR to include a fix for a potential XSS vulnerability in the
idleAPI sample.Key Changes:
api-samples/idle/history.jsto replace insecure.innerHTMLusage with safe DOM manipulation (textContentandreplaceChildren). This mitigates potential XSS risks from untrusted data in the history log.@rollup/plugin-commonjsand@rollup/plugin-node-resolveto their latest stable versions across multiple functional samples:These changes ensure the samples follow modern security standards and protect against potential supply chain vulnerabilities.