And there is fire where we walk.
Posts
DOMPurify 3.4.1 is out with lots of small improvements.
Among them, a better test suite, a small fuzzer, several fixes and hardenings, and as usually we hope all went well 😅
To all the OSS projects getting swamped by AI tickets right now...
IT IS TOTALLY YOUR OWN FAULT.
The easy fix is to write better code.
You are welcome, this advice was free.
*ducks*
In anticipation of possibly upcoming waves of OSS bugs as well maybe increasing amounts of real attacks, we have been busy hardening DOMPurify.
Look at those shiny badges and improvements, LOOK OMG 😱
https://github.com/cure53/dompurify?tab=readme-ov-file#dompurify
Work in progress of course, but lots got done this week 💪🏻
Version 3.4.0 of DOMPurify was released today, addressing a large number of issues reported by LLMs and real people alike.
Thanks to all who contributed.
https://github.com/cure53/DOMPurify/releases/tag/3.4.0
We hope everything went smoothly and that no one was overlooked in the release notes.
Here's everybody's space heroes having a great time with DJT.
https://edition.cnn.com/2026/04/07/science/video/donald-trump-call-artemis-ii-hnk-digvid
DOMPurify 2.5.9 and DOMPurify 3.3.2 were released today in a rush to fix a security issue caused by jsdom's faulty tag parsing.
A total of four people reported the exacty same bug within a window of three days.
One did so via email, thank you. One did so via private security advisory, thank you too.
One however simply published a ticket for everyone to see, the other one just dropped a CVE on us without a working fix release. Thanks for nothing.
We have slightly updated the publicly available contract templates for NDA, MSA and DPA. File format is ODT as usual.
Feel free to, just as before, use them as you see it fit for your own purposes 😄
DOMPurify 3.3.0 is out. You can now configure which tags can have which attributes much more easily.
https://github.com/cure53/DOMPurify/releases/tag/3.3.0
Thanks again to everyone who contributed to and supported the project. ❤️