Skip to content

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Oct 23, 2024

This PR contains the following updates:

Package Change Age Confidence
mermaid 10.6.1 -> 10.9.3 age confidence

GitHub Vulnerability Alerts

GHSA-m4gq-x24j-jpmf

The following bundled files within the Mermaid NPM package contain a bundled version of DOMPurify that is vulnerable to GHSA-mmhx-hmjr-r674, potentially resulting in an XSS attack.

This affects the built:

  • dist/mermaid.min.js
  • dist/mermaid.js
  • dist/mermaid.esm.mjs
  • dist/mermaid.esm.min.mjs

This will also affect users that use the above files via a CDN link, e.g. https://cdn.jsdelivr.net/npm/[email protected]/dist/mermaid.min.js

Users that use the default NPM export of mermaid, e.g. import mermaid from 'mermaid', or the dist/mermaid.core.mjs file, do not use this bundled version of DOMPurify, and can easily update using their package manager with something like npm audit fix.

Patches

  • develop branch: 6c785c93166c151d27d328ddf68a13d9d65adc00
  • backport to v10: 92a07ffe40aab2769dd1c3431b4eb5beac282b34

Release Notes

mermaid-js/mermaid (mermaid)

v10.9.3

Compare Source

Updates the bundled version of dependencies in the following files:

  • dist/mermaid.min.js
  • dist/mermaid.js
  • dist/mermaid.esm.mjs
  • dist/mermaid.esm.min.mjs

If you are not using these files (e.g. you are using the default NPM export of mermaid, e.g. import mermaid from 'mermaid', or you are using dist/mermaid.core.mjs), this release is identical to v10.9.2.

This is to avoid potential security issues in KaTeX and DOMPurify, see:

These dependencies have already been updated in v11.0.0.

Changelog

Chore
  • Updates the bundled version of KaTeX to 0.16.11 (2bedd0e)
  • Updates the bundled version of DOMPurify to 3.1.6 (92a07ff)

Full Changelog: mermaid-js/mermaid@v10.9.2...v10.9.3

v10.9.2

Compare Source

This release back-ports #​5914 to the v10 release line to fix #​5904 (an incompatibility between mermaid and DOMPurify v3.1.7)

Patch Changes

Full Changelog: mermaid-js/mermaid@v10.9.1...v10.9.2

v10.9.1

Compare Source

What's Changed

BugFixes

  • Cleaning of labels in Block diagram by @​knsv

Docs

New Contributors

Full Changelog: mermaid-js/mermaid@v10.9.0...v10.9.1

v10.9.0

Compare Source

Release Notes

We now have Katex support!

image
Demo

🚀 Features

🧰 Maintenance

📚 Documentation

🎉 Thanks to all contributors helping with this release! 🎉

v10.8.0

Compare Source

v10.8.0

Features

image

Documentation

Bug fixes

Chores

New Contributors

Full Changelog: mermaid-js/mermaid@v10.7.0...v10.8.0

v10.7.0

Compare Source

Release Notes

🚀 Features

🐛 Bug Fixes

🧰 Maintenance

📚 Documentation

🎉 Thanks to all contributors helping with this release! 🎉


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Copy link

vercel bot commented Oct 23, 2024

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Preview Comments Updated (UTC)
wiki Ignored Ignored Preview Sep 25, 2025 2:45pm

@renovate renovate bot changed the title chore(deps): update dependency mermaid to v10.9.3 [security] chore(deps): update dependency mermaid to v10.9.3 [security] - autoclosed Dec 8, 2024
@renovate renovate bot closed this Dec 8, 2024
@renovate renovate bot deleted the renovate/npm-mermaid-vulnerability branch December 8, 2024 18:42
@renovate renovate bot changed the title chore(deps): update dependency mermaid to v10.9.3 [security] - autoclosed chore(deps): update dependency mermaid to v10.9.3 [security] Dec 8, 2024
@renovate renovate bot reopened this Dec 8, 2024
@renovate renovate bot force-pushed the renovate/npm-mermaid-vulnerability branch from 24b244d to 81fa2eb Compare December 8, 2024 22:34
@renovate renovate bot force-pushed the renovate/npm-mermaid-vulnerability branch 2 times, most recently from 2d2ef06 to c1179a5 Compare January 30, 2025 14:41
@renovate renovate bot force-pushed the renovate/npm-mermaid-vulnerability branch from c1179a5 to 316a557 Compare February 9, 2025 17:35
@renovate renovate bot force-pushed the renovate/npm-mermaid-vulnerability branch from 316a557 to c95e015 Compare March 3, 2025 12:09
@renovate renovate bot force-pushed the renovate/npm-mermaid-vulnerability branch 3 times, most recently from 860cf77 to b7a8b70 Compare March 17, 2025 17:56
@renovate renovate bot force-pushed the renovate/npm-mermaid-vulnerability branch from b7a8b70 to 2ae52c4 Compare April 8, 2025 12:31
@renovate renovate bot force-pushed the renovate/npm-mermaid-vulnerability branch from 2ae52c4 to 762f84c Compare April 24, 2025 07:28
@renovate renovate bot force-pushed the renovate/npm-mermaid-vulnerability branch from 762f84c to 1cd43fa Compare May 19, 2025 18:14
@renovate renovate bot force-pushed the renovate/npm-mermaid-vulnerability branch from 1cd43fa to 55d1e9c Compare June 4, 2025 06:03
@renovate renovate bot force-pushed the renovate/npm-mermaid-vulnerability branch from 55d1e9c to 8a766c1 Compare June 22, 2025 14:57
@renovate renovate bot force-pushed the renovate/npm-mermaid-vulnerability branch from 8a766c1 to 1bdf063 Compare July 2, 2025 16:09
@renovate renovate bot force-pushed the renovate/npm-mermaid-vulnerability branch 2 times, most recently from 19c2520 to 57fd4dd Compare August 13, 2025 14:55
@renovate renovate bot force-pushed the renovate/npm-mermaid-vulnerability branch from 57fd4dd to 191e438 Compare August 31, 2025 14:07
@renovate renovate bot force-pushed the renovate/npm-mermaid-vulnerability branch from 191e438 to 7e7b179 Compare September 25, 2025 14:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants