fix: SVGO DoS through entity expansion in DOCTYPE (#19359)

Resolves [Dependabot Alert
604](https://github.com/twentyhq/twenty/security/dependabot/604) and
[Dependabot Alert
605](https://github.com/twentyhq/twenty/security/dependabot/605).
This commit is contained in:
Abdullah. 2026-04-07 12:15:35 +05:00 committed by GitHub
parent 35b76539cc
commit 8c9228cb2b
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -24158,13 +24158,6 @@ __metadata:
languageName: node
linkType: hard
"@trysound/sax@npm:0.2.0":
version: 0.2.0
resolution: "@trysound/sax@npm:0.2.0"
checksum: 10c0/44907308549ce775a41c38a815f747009ac45929a45d642b836aa6b0a536e4978d30b8d7d680bbd116e9dd73b7dbe2ef0d1369dcfc2d09e83ba381e485ecbe12
languageName: node
linkType: hard
"@ts-gql/tag@npm:^0.7.3":
version: 0.7.3
resolution: "@ts-gql/tag@npm:0.7.3"
@ -56257,6 +56250,13 @@ __metadata:
languageName: node
linkType: hard
"sax@npm:^1.5.0":
version: 1.6.0
resolution: "sax@npm:1.6.0"
checksum: 10c0/e5593f4a91eb25761a688c4d96902e4e95a0dd6017bc65146b6f21236e3d715cf893333b76bc758923c9574c2fb5a7a76c3a81e96ea15432f2624f906c027c1e
languageName: node
linkType: hard
"saxes@npm:^6.0.0":
version: 6.0.0
resolution: "saxes@npm:6.0.0"
@ -58874,36 +58874,36 @@ __metadata:
linkType: hard
"svgo@npm:^2.8.0":
version: 2.8.0
resolution: "svgo@npm:2.8.0"
version: 2.8.2
resolution: "svgo@npm:2.8.2"
dependencies:
"@trysound/sax": "npm:0.2.0"
commander: "npm:^7.2.0"
css-select: "npm:^4.1.3"
css-tree: "npm:^1.1.3"
csso: "npm:^4.2.0"
picocolors: "npm:^1.0.0"
sax: "npm:^1.5.0"
stable: "npm:^0.1.8"
bin:
svgo: bin/svgo
checksum: 10c0/0741f5d5cad63111a90a0ce7a1a5a9013f6d293e871b75efe39addb57f29a263e45294e485a4d2ff9cc260a5d142c8b5937b2234b4ef05efdd2706fb2d360ecc
svgo: ./bin/svgo
checksum: 10c0/a3a533e1678aecdfa1c67f06d71f104da7ef574a3f63a8dfeda10368b42428c67d09a06b4eee233c5ed49ac815f1febb6193cba0f611a21bfc00366d7930205d
languageName: node
linkType: hard
"svgo@npm:^3.0.2":
version: 3.3.2
resolution: "svgo@npm:3.3.2"
version: 3.3.3
resolution: "svgo@npm:3.3.3"
dependencies:
"@trysound/sax": "npm:0.2.0"
commander: "npm:^7.2.0"
css-select: "npm:^5.1.0"
css-tree: "npm:^2.3.1"
css-what: "npm:^6.1.0"
csso: "npm:^5.0.5"
picocolors: "npm:^1.0.0"
sax: "npm:^1.5.0"
bin:
svgo: ./bin/svgo
checksum: 10c0/a6badbd3d1d6dbb177f872787699ab34320b990d12e20798ecae915f0008796a0f3c69164f1485c9def399e0ce0a5683eb4a8045e51a5e1c364bb13a0d9f79e1
checksum: 10c0/06568c6b0430f96748c557f0b17dc7de79b19fa16d13d7523527ede0ec727fc6d8e6a10e13ff106dc4372d2e6063a1dca7c455c495efb1b83857480425f9b965
languageName: node
linkType: hard