Skip to content

fix(deps-dev): bump svgo from 3.3.4 to 3.3.5 - #1212

Merged
dkotter merged 1 commit into
developfrom
dependabot/npm_and_yarn/svgo-3.3.5
Sep 17, 2026
Merged

dkotter merged 1 commit into
developfrom
dependabot/npm_and_yarn/svgo-3.3.5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

Bumps svgo from 3.3.4 to 3.3.5.

Release notes

Sourced from svgo's releases.

v3.3.5

What's Changed

Security

  • Backport the removeScriptElement hardening from SVGO v4 in #2269:
    • reject executable data: URLs and legacy vbscript: URLs
    • sanitize executable HTML inside <foreignObject> elements
    • handle namespace-prefixed SVG anchors and URL schemes containing ASCII tabs or newlines

This addresses GHSA-4vpr-x523-8j87 and GHSA-w27v-7q3p-w38r for the v3 release line.

Support

SVGO v3 is not officially supported; please consider upgrading to SVGO v4. This security fix has been backported, but there is no commitment to backport more complex changes in the future.

See the migration guide from v3 to v4.

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for svgo since your current version.


Open WordPress Playground Preview

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 17, 2026
@dependabot
dependabot Bot requested review from a team, dkotter and jeffpaul as code owners September 17, 2026 11:49
@github-actions github-actions Bot added the needs:code-review This requires code review. label Sep 17, 2026
@github-actions

Copy link
Copy Markdown

✅ WordPress Plugin Check Report

✅ Status: Passed

📊 Report

All checks passed! No errors or warnings found.


🤖 Generated by WordPress Plugin Check Action • Learn more about Plugin Check

@jeffpaul jeffpaul added this to the 4.0.0 milestone Sep 17, 2026
@jeffpaul jeffpaul moved this to Code Review in Open Source Practice Sep 17, 2026
@dkotter

dkotter commented Sep 17, 2026

Copy link
Copy Markdown
Collaborator

@dependabot rebase

Bumps [svgo](https://github.com/svg/svgo) from 3.3.4 to 3.3.5.
- [Release notes](https://github.com/svg/svgo/releases)
- [Commits](svg/svgo@v3.3.4...v3.3.5)

---
updated-dependencies:
- dependency-name: svgo
  dependency-version: 3.3.5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/svgo-3.3.5 branch from 7242125 to f913c4b Compare September 17, 2026 13:56
@github-project-automation github-project-automation Bot moved this from Code Review to QA Testing in Open Source Practice Sep 17, 2026
@dkotter
dkotter merged commit 5bc11ec into develop Sep 17, 2026
29 of 30 checks passed
@dkotter
dkotter deleted the dependabot/npm_and_yarn/svgo-3.3.5 branch September 17, 2026 15:25
@github-project-automation github-project-automation Bot moved this from QA Testing to Done in Open Source Practice Sep 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file needs:code-review This requires code review.

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

2 participants