Skip to content

dompurify 3.4.4

  • Added the selectedcontent element to default allow-list, thanks @lukewarlow
  • Added the command and commandfor attributes to default allowed-list, thanks @lukewarlow
  • Added better template scrubbing for IN_PLACE operations, thanks @DEMON1A
  • Added stronger checks for cross-realm windows, thanks @DEMON1A & @fg0x0
  • Updated demo website and made sure it uses the latest from main
  • Updated existing workflows, fuzzer, dependabot, etc., added more tests
  • Bumped several dependencies where possible

🚨 This release had been flagged as deprecated, please use DOMPurify 3.4.5 instead 🚨