Skip to content

Update dependency league/commonmark to v2.8.2#87

Merged
renovate[bot] merged 1 commit intomasterfrom
renovate/league-commonmark-2.x-lockfile
Mar 19, 2026
Merged

Update dependency league/commonmark to v2.8.2#87
renovate[bot] merged 1 commit intomasterfrom
renovate/league-commonmark-2.x-lockfile

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Mar 19, 2026

This PR contains the following updates:

Package Change Age Confidence
league/commonmark (source) 2.8.12.8.2 age confidence

Release Notes

thephpleague/commonmark (league/commonmark)

v2.8.2

Compare Source

This is a security release to address an issue where the allowed_domains setting for the Embed extension can be bypassed, resulting in a possible SSRF and XSS vulnerabilities.

Fixed
  • Fixed DomainFilteringAdapter hostname boundary bypass where domains like youtube.com.evil could match an allowlist entry for youtube.com (GHSA-hh8v-hgvp-g3f5)

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the dependencies Pull requests that update a dependency file label Mar 19, 2026
@renovate renovate bot merged commit daa2a55 into master Mar 19, 2026
5 checks passed
@renovate renovate bot deleted the renovate/league-commonmark-2.x-lockfile branch March 19, 2026 21:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants