Skip to content

[fix](sec): KaTeX \htmlData does not validate attribute names#707

Merged
RalphHightower merged 2 commits intomainfrom
codespace-humble-guacamole-pgjjvrxx99v366j4
Jan 18, 2025
Merged

[fix](sec): KaTeX \htmlData does not validate attribute names#707
RalphHightower merged 2 commits intomainfrom
codespace-humble-guacamole-pgjjvrxx99v366j4

Conversation

@RalphHightower
Copy link
Copy Markdown
Owner

No description provided.

@RalphHightower RalphHightower added improve Improvement version update/upgrade Bump version up npm package npm – JavaScript Software Registry vulnerability Vulnerability problem labels Jan 18, 2025
@RalphHightower RalphHightower self-assigned this Jan 18, 2025
@RalphHightower RalphHightower changed the title [fix](sec): Codespace humble guacamole pgjjvrxx99v366j4 [fix](sec): KaTeX \htmlData does not validate attribute names Jan 18, 2025
@RalphHightower RalphHightower merged commit f8828b9 into main Jan 18, 2025
@RalphHightower
Copy link
Copy Markdown
Owner Author

Run ruby/setup-ruby@868b3f088412f139260f27f5b148179b9dd6b008
  with:
    ruby-version: 3.3.6
    bundler-cache: true
    cache-version: 3
Modifying PATH
  Entries added to PATH to use selected Ruby:
    /opt/hostedtoolcache/Ruby/3.3.6/x64/bin
Downloading Ruby
  https://github.com/ruby/ruby-builder/releases/download/toolcache/ruby-3.3.6-ubuntu-24.04.tar.gz
  Took   0.79 seconds
Extracting  Ruby
  /usr/bin/tar -xz -C /opt/hostedtoolcache/Ruby/3.3.6 -f /home/runner/work/_temp/e7a287fe-b65b-4942-b949-d6997a7e1641
  Took   0.46 seconds
Print Ruby version
  /opt/hostedtoolcache/Ruby/3.3.6/x64/bin/ruby --version
  ruby 3.3.6 (2024-11-05 revision 75015d4c1f) [x86_64-linux]
  Took   0.02 seconds
Installing Bundler
  Using Bundler 2.6.2 from Gemfile.lock BUNDLED WITH 2.6.2
  /opt/hostedtoolcache/Ruby/3.3.6/x64/bin/gem install bundler -v 2.6.2
  Successfully installed bundler-2.6.2
  1 gem installed
  Took   0.44 seconds
> bundle install
/opt/hostedtoolcache/Ruby/3.3.6/x64/bin/bundle config --local path /home/runner/work/blog/blog/vendor/bundle
/opt/hostedtoolcache/Ruby/3.3.6/x64/bin/bundle config --local deployment true
Cache key: setup-ruby-bundler-cache-v6-ubuntu-24.04-x64-ruby-3.3.6-wd-/home/runner/work/blog/blog-with--without--only--v-3-Gemfile.lock-17a9d40c34e677cfbc17f41ac2ca4b5284e3ff6b590041a63d3b92cd6e4a6a88
Received 0 of 38133546 (0.0%), 0.0 MBs/sec
Cache Size: ~36 MB (38133546 B)
/usr/bin/tar -xf /home/runner/work/_temp/385bf91f-573f-407c-8be8-97d1fd980e67/cache.tzst -P -C /home/runner/work/blog/blog --use-compress-program unzstd
Received 38133546 of 38133546 (100.0%), 18.2 MBs/sec
Cache restored successfully
Found cache for key: setup-ruby-bundler-cache-v6-ubuntu-24.04-x64-ruby-3.3.6-wd-/home/runner/work/blog/blog-with--without--only--v-3-Gemfile.lock-4971da0746f58f57b53c6664c280dcfdd0ff058405aea41017f0417887a2794d
/opt/hostedtoolcache/Ruby/3.3.6/x64/bin/bundle install --jobs 4
The dependencies in your gemfile changed, but the lockfile can't be updated
because frozen mode is set

You have added to the Gemfile:
* sassc-embedded (~> 1.80, >= 1.80.1)
* jekyll-paginate-v2 (~> 3.0)
* sqlite3 (~> 1.4, >= 1.4.4)
* csv (~> 3.3, >= 3.3.2)

You have deleted from the Gemfile:
* csv (~> 3.3)
* jekyll-paginate (~> 1.1)
* sassc-embedded (~> 1.78)

Run `bundle install` elsewhere and add the updated Gemfile to version control.
If this is a development machine, remove the Gemfile.lock freeze by running
`bundle config set frozen false`.
Error: The process '/opt/hostedtoolcache/Ruby/3.3.6/x64/bin/bundle' failed with exit code 16

@RalphHightower RalphHightower added the action – failure Failure during an Action label Jan 19, 2025
@RalphHightower RalphHightower deleted the codespace-humble-guacamole-pgjjvrxx99v366j4 branch June 24, 2025 04:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action – failure Failure during an Action improve Improvement npm package npm – JavaScript Software Registry version update/upgrade Bump version up vulnerability Vulnerability problem

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant