chore(deps): bump python-multipart 0.0.22→0.0.26 and dompurify 3.3.3→3.4.0

python-multipart 0.0.26 closes CVE-2026-40347 (GHSA-mj87-hwqh-73pj), a
  DoS triggered by large preamble/epilogue data around a multipart
  boundary. Bambuddy consumes python-multipart transitively through
  FastAPI/Starlette for form and file-upload parsing, so multipart routes
  (backup restore, project thumbnail upload, etc.) were exposed.

  dompurify 3.4.0 picks up the fix for GHSA-39q2-94rc-95cp (function-form
  ADD_TAGS could bypass FORBID_TAGS). Bambuddy's two call sites use only
  array-form ALLOWED_TAGS/ALLOWED_ATTR, so the specific bypass was not
  reachable, but the bump still hardens the sanitizer and clears the
  audit warning.

  requirements.txt floor raised to python-multipart>=0.0.26;
  frontend/package.json caret pinned to ^3.4.0; npm audit and pip audit
  both report zero outstanding advisories after the bumps.
This commit is contained in:
maziggy
2026-04-16 08:47:40 +02:00
parent c73c23b083
commit 63b3cad8d8
6 changed files with 107 additions and 104 deletions
+1 -1
View File
@@ -28,7 +28,7 @@
"@tiptap/react": "^3.11.1",
"@tiptap/starter-kit": "^3.11.1",
"@types/three": "^0.181.0",
"dompurify": "^3.3.3",
"dompurify": "^3.4.0",
"gcode-preview": "^2.18.0",
"i18next": "25.6.3",
"i18next-browser-languagedetector": "^8.2.0",