Added a logger option: pass any console-shaped object, with debug, info, warn and error methods, and sanitize-html's own diagnostics are delivered to it rather than to the console, so an application with a logging pipeline of its own can route them. Missing methods, and no option at all, fall back to the console. Those messages also lost their decorative line breaks and warning icon, so each is now a single line of text; their wording is otherwise unchanged.
Fixes
allowedSchemesByTag is now applied to srcset and imagesrcset URLs. Previously the per-tag lookup used the attribute name instead of the tag name, so these attributes always fell back to the global allowedSchemes and ignored a tag-specific scheme allowlist. Thanks to spokodev for the fix.
Starting in version 2.17.6, sanitize-html began escaping any markup preserved inside a disallowed iframe tag, which was a change
in behavior due to an upstream change in htmlparser2. This fix ensures such "fallback markup" is preserved without escaping, but also
fully sanitized according to the same rules as the original input. Thanks to sumitjhacodes for
the fix.
Security
When meta was allowed together with its http-equiv and content attributes, the destination URL of a <meta http-equiv="refresh" content="0;url=..."> was never checked against allowedSchemes, because it is embedded in content rather than being an attribute of its own. So javascript:, data: and other disallowed destinations passed through. The refresh URL is now extracted the way browsers do it, allowing for the different spellings, separators, quoting and letter case of url=, and checked against allowedSchemes (or allowedSchemesByTag.meta). If it is rejected, or the content cannot be parsed as a refresh, the content attribute is removed. content on other meta elements is unchanged. The default configuration does not allow meta and was not affected (CWE-79, CWE-601, GHSA-cv27-6wvh-8x7j).
Thanks to adrbogacz for reporting the vulnerability.
When noscript is listed in nonTextTags, the discarded region could end too early. Browsers with scripting enabled treat <noscript> content as raw text up to the first </noscript>, but the underlying parser treats it as markup, so an end tag for an enclosing element inside <noscript> closed it implicitly and the rest of its content was emitted as ordinary sanitized markup. The discard region now continues until the point where a browser would end the <noscript> element, while implied closes of other nonTextTags such as <option> behave as before (CWE-79, CWE-436, GHSA-x3q4-9hxx-gx8m).
The check that drops SVG animation elements (animate, animateColor, animateMotion, animateTransform, set) when they retarget a URL attribute such as href compared the full tag name, so a namespace-prefixed spelling like svg:animate was not recognized when such tags were allowed (for example with allowedTags: false). In XML serializations such as XHTML or standalone SVG, the prefixed element is a real animation element and could retarget a link to a javascript: URL after sanitization. The element and attributeName are now matched by their local names, ignoring any prefix (CWE-79, CWE-184, GHSA-374f-7chj-9948).
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [npm](https://docs.npmjs.com/) ([source](https://github.com/npm/cli)) | [`12.1.0` → `12.2.0`](https://renovatebot.com/diffs/npm/npm/12.1.0/12.2.0) |  |  |
| [sanitize-html](https://github.com/apostrophecms/apostrophe/tree/main/packages/sanitize-html#readme) ([source](https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html)) | [`2.17.7` → `2.18.0`](https://renovatebot.com/diffs/npm/sanitize-html/2.17.7/2.18.0) |  |  |
---
### Release Notes
<details>
<summary>npm/cli (npm)</summary>
### [`v12.2.0`](https://github.com/npm/cli/blob/HEAD/CHANGELOG.md#1220-2026-09-30)
[Compare Source](https://github.com/npm/cli/compare/v12.1.0...v12.2.0)
##### Features
- [`9741b64`](https://github.com/npm/cli/commit/9741b645b011ae83c9dda66c9b0d5fe0dce9c766) [#​10038](https://github.com/npm/cli/pull/10038) dist-tag: support OIDC authentication ([#​10038](https://github.com/npm/cli/issues/10038)) ([@​reggi](https://github.com/reggi), [@​Copilot](https://github.com/Copilot))
##### Documentation
- [`0c3b82a`](https://github.com/npm/cli/commit/0c3b82a9a612c3f9399d35c28c86708b1f8ea7d4) [#​10017](https://github.com/npm/cli/pull/10017) update npm stage docs to reflect that it can create new packages ([#​10017](https://github.com/npm/cli/issues/10017)) ([@​shmam](https://github.com/shmam), [@​Copilot](https://github.com/Copilot))
##### Dependencies
- [workspace](https://github.com/npm/cli/releases/tag/config-v11.2.0): `@npmcli/config@11.2.0`
</details>
<details>
<summary>apostrophecms/apostrophe (sanitize-html)</summary>
### [`v2.18.0`](https://github.com/apostrophecms/apostrophe/blob/HEAD/packages/sanitize-html/CHANGELOG.md#2180-2026-09-30)
[Compare Source](https://github.com/apostrophecms/apostrophe/compare/sanitize-html@2.17.7...sanitize-html@2.18.0)
##### Adds
- Added a `logger` option: pass any console-shaped object, with `debug`, `info`, `warn` and `error` methods, and sanitize-html's own diagnostics are delivered to it rather than to the console, so an application with a logging pipeline of its own can route them. Missing methods, and no option at all, fall back to the console. Those messages also lost their decorative line breaks and warning icon, so each is now a single line of text; their wording is otherwise unchanged.
##### Fixes
- `allowedSchemesByTag` is now applied to `srcset` and `imagesrcset` URLs. Previously the per-tag lookup used the attribute name instead of the tag name, so these attributes always fell back to the global `allowedSchemes` and ignored a tag-specific scheme allowlist. Thanks to
[spokodev](https://github.com/spokodev) for the fix.
- Starting in version 2.17.6, `sanitize-html` began escaping any markup preserved inside a disallowed iframe tag, which was a change
in behavior due to an upstream change in `htmlparser2`. This fix ensures such "fallback markup" is preserved without escaping, but also
fully sanitized according to the same rules as the original input. Thanks to [sumitjhacodes](https://github.com/sumitjhacodes) for
the fix.
##### Security
- When `meta` was allowed together with its `http-equiv` and `content` attributes, the destination URL of a `<meta http-equiv="refresh" content="0;url=...">` was never checked against `allowedSchemes`, because it is embedded in `content` rather than being an attribute of its own. So `javascript:`, `data:` and other disallowed destinations passed through. The refresh URL is now extracted the way browsers do it, allowing for the different spellings, separators, quoting and letter case of `url=`, and checked against `allowedSchemes` (or `allowedSchemesByTag.meta`). If it is rejected, or the content cannot be parsed as a refresh, the `content` attribute is removed. `content` on other `meta` elements is unchanged. The default configuration does not allow `meta` and was not affected (CWE-79, CWE-601, GHSA-cv27-6wvh-8x7j).
Thanks to [adrbogacz](https://github.com/adrbogacz) for reporting the vulnerability.
- When `noscript` is listed in `nonTextTags`, the discarded region could end too early. Browsers with scripting enabled treat `<noscript>` content as raw text up to the first `</noscript>`, but the underlying parser treats it as markup, so an end tag for an enclosing element inside `<noscript>` closed it implicitly and the rest of its content was emitted as ordinary sanitized markup. The discard region now continues until the point where a browser would end the `<noscript>` element, while implied closes of other `nonTextTags` such as `<option>` behave as before (CWE-79, CWE-436, GHSA-x3q4-9hxx-gx8m).
Thanks to [joaquiniglesiaslug](https://github.com/joaquiniglesiaslug) for reporting the vulnerability.
- The check that drops SVG animation elements (`animate`, `animateColor`, `animateMotion`, `animateTransform`, `set`) when they retarget a URL attribute such as `href` compared the full tag name, so a namespace-prefixed spelling like `svg:animate` was not recognized when such tags were allowed (for example with `allowedTags: false`). In XML serializations such as XHTML or standalone SVG, the prefixed element is a real animation element and could retarget a link to a `javascript:` URL after sanitization. The element and `attributeName` are now matched by their local names, ignoring any prefix (CWE-79, CWE-184, GHSA-374f-7chj-9948).
Thanks to [Kai Aizen (SnailSploit)](https://github.com/SnailSploit) for reporting the vulnerability.
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions) if that's undesired.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMjYuMCIsInVwZGF0ZWRJblZlciI6IjQ0LjEyNi4wIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImF1dG9tYXRlZCIsImRlcGVuZGVuY2llcyJdfQ==-->
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
This PR contains the following updates:
12.1.0→12.2.02.17.7→2.18.0Release Notes
npm/cli (npm)
v12.2.0Compare Source
Features
9741b64#10038 dist-tag: support OIDC authentication (#10038) (@reggi, @Copilot)Documentation
0c3b82a#10017 update npm stage docs to reflect that it can create new packages (#10017) (@shmam, @Copilot)Dependencies
@npmcli/config@11.2.0apostrophecms/apostrophe (sanitize-html)
v2.18.0Compare Source
Adds
loggeroption: pass any console-shaped object, withdebug,info,warnanderrormethods, and sanitize-html's own diagnostics are delivered to it rather than to the console, so an application with a logging pipeline of its own can route them. Missing methods, and no option at all, fall back to the console. Those messages also lost their decorative line breaks and warning icon, so each is now a single line of text; their wording is otherwise unchanged.Fixes
allowedSchemesByTagis now applied tosrcsetandimagesrcsetURLs. Previously the per-tag lookup used the attribute name instead of the tag name, so these attributes always fell back to the globalallowedSchemesand ignored a tag-specific scheme allowlist. Thanks tospokodev for the fix.
sanitize-htmlbegan escaping any markup preserved inside a disallowed iframe tag, which was a changein behavior due to an upstream change in
htmlparser2. This fix ensures such "fallback markup" is preserved without escaping, but alsofully sanitized according to the same rules as the original input. Thanks to sumitjhacodes for
the fix.
Security
When
metawas allowed together with itshttp-equivandcontentattributes, the destination URL of a<meta http-equiv="refresh" content="0;url=...">was never checked againstallowedSchemes, because it is embedded incontentrather than being an attribute of its own. Sojavascript:,data:and other disallowed destinations passed through. The refresh URL is now extracted the way browsers do it, allowing for the different spellings, separators, quoting and letter case ofurl=, and checked againstallowedSchemes(orallowedSchemesByTag.meta). If it is rejected, or the content cannot be parsed as a refresh, thecontentattribute is removed.contenton othermetaelements is unchanged. The default configuration does not allowmetaand was not affected (CWE-79, CWE-601, GHSA-cv27-6wvh-8x7j).Thanks to adrbogacz for reporting the vulnerability.
When
noscriptis listed innonTextTags, the discarded region could end too early. Browsers with scripting enabled treat<noscript>content as raw text up to the first</noscript>, but the underlying parser treats it as markup, so an end tag for an enclosing element inside<noscript>closed it implicitly and the rest of its content was emitted as ordinary sanitized markup. The discard region now continues until the point where a browser would end the<noscript>element, while implied closes of othernonTextTagssuch as<option>behave as before (CWE-79, CWE-436, GHSA-x3q4-9hxx-gx8m).Thanks to joaquiniglesiaslug for reporting the vulnerability.
The check that drops SVG animation elements (
animate,animateColor,animateMotion,animateTransform,set) when they retarget a URL attribute such ashrefcompared the full tag name, so a namespace-prefixed spelling likesvg:animatewas not recognized when such tags were allowed (for example withallowedTags: false). In XML serializations such as XHTML or standalone SVG, the prefixed element is a real animation element and could retarget a link to ajavascript:URL after sanitization. The element andattributeNameare now matched by their local names, ignoring any prefix (CWE-79, CWE-184, GHSA-374f-7chj-9948).Thanks to Kai Aizen (SnailSploit) for reporting the vulnerability.
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate CLI.