Skip to content

build(deps): bump jodit from 4.16.0 to 4.17.1 - #4744

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/jodit-4.17.1
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/jodit-4.17.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor

Bumps jodit from 4.16.0 to 4.17.1.

Release notes

Sourced from jodit's releases.

4.17.1

🐛 Bug Fix

  • GHSA-jhhp-r3r7-v2cg Security: cleanHTML.removeEventAttributes was not enforced by the background sanitizing pass — sanitizeHTMLElement() only stripped onerror, so any other on* handler survived on markup that reached the editable area without safeHTML, and a drop from another window was inserted by the browser natively, unsanitized, because the drop handler was only armed after a dragstart seen in the same window. The background pass now strips every on* attribute, and drops always go through the paste plugin's sanitizing path. Reported by David Vieira Kurz (HiSolutions AG).

4.17.0

💥 Breaking Change

  • #1523 The file popup's Upload tab inserts every uploaded file as a link — an image too, since the file button was chosen over the image button. Before, an uploaded image went in as <img> through uploader.defaultHandlerSuccess. The new file.defaultHandlerSuccess option replaces what the tab inserts; to keep the old behaviour: file: { defaultHandlerSuccess(data) { this.o.uploader.defaultHandlerSuccess.call(this, data); } }. Thanks @​brendon.

🚀 New Feature

  • #1509 The video popup has an Upload tab when an uploader is configured (uploader.url or uploader.customUploadFunction, unless uploader.showTabInFileSelector is false). Each uploaded file goes in as <video controls src>, and the new video.defaultHandlerSuccess option replaces that insertion. The tab is built by the new UploadTab helper, which the image and file popups use as well. Thanks @​brendon.
  • #1531 The image popup's align button shows the alignment of the image's line for an image with no alignment of its own, instead of always the left icon. Thanks @​brendon.

🐛 Bug Fix

  • Opening the source view before ACE has loaded shows a plain textarea; when ACE arrives it now takes over that textarea's text, selection and focus as they are. Before, it was refilled from the WYSIWYG value, which dropped what had been typed since the last sync and normalised half-typed markup. Likewise js-beautify, arriving after the source view opened, formats the view right away when nothing has been typed into it, and leaves it alone otherwise.

4.16.1

🐛 Bug Fix

  • #1526 Text typed into the source view is no longer replaced when js-beautify finishes loading after the source view opens; the beautifier formats the source view from the next time it opens. Thanks @​brendon.
  • #1528 In Safari, selecting a block image with text after it no longer highlights the rest of the image's line, and no highlight is left behind after changing the image's alignment. Thanks @​brendon.
Changelog

Sourced from jodit's changelog.

4.17.1

🐛 Bug Fix

  • GHSA-jhhp-r3r7-v2cg Security: cleanHTML.removeEventAttributes was not enforced by the background sanitizing pass — sanitizeHTMLElement() only stripped onerror, so any other on* handler survived on markup that reached the editable area without safeHTML, and a drop from another window was inserted by the browser natively, unsanitized, because the drop handler was only armed after a dragstart seen in the same window. The background pass now strips every on* attribute, and drops always go through the paste plugin's sanitizing path. Reported by David Vieira Kurz (HiSolutions AG).

4.17.0

💥 Breaking Change

  • #1523 The file popup's Upload tab inserts every uploaded file as a link — an image too, since the file button was chosen over the image button. Before, an uploaded image went in as <img> through uploader.defaultHandlerSuccess. The new file.defaultHandlerSuccess option replaces what the tab inserts; to keep the old behaviour: file: { defaultHandlerSuccess(data) { this.o.uploader.defaultHandlerSuccess.call(this, data); } }. Thanks @​brendon.

🚀 New Feature

  • #1509 The video popup has an Upload tab when an uploader is configured (uploader.url or uploader.customUploadFunction, unless uploader.showTabInFileSelector is false). Each uploaded file goes in as <video controls src>, and the new video.defaultHandlerSuccess option replaces that insertion. The tab is built by the new UploadTab helper, which the image and file popups use as well. Thanks @​brendon.
  • #1531 The image popup's align button shows the alignment of the image's line for an image with no alignment of its own, instead of always the left icon. Thanks @​brendon.

🐛 Bug Fix

  • Opening the source view before ACE has loaded shows a plain textarea; when ACE arrives it now takes over that textarea's text, selection and focus as they are. Before, it was refilled from the WYSIWYG value, which dropped what had been typed since the last sync and normalised half-typed markup. Likewise js-beautify, arriving after the source view opened, formats the view right away when nothing has been typed into it, and leaves it alone otherwise.

4.16.1

🐛 Bug Fix

  • #1526 Text typed into the source view is no longer replaced when js-beautify finishes loading after the source view opens; the beautifier formats the source view from the next time it opens. Thanks @​brendon.
  • #1528 In Safari, selecting a block image with text after it no longer highlights the rest of the image's line, and no highlight is left behind after changing the image's alignment. Thanks @​brendon.
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [jodit](https://github.com/xdan/jodit) from 4.16.0 to 4.17.1.
- [Release notes](https://github.com/xdan/jodit/releases)
- [Changelog](https://github.com/xdan/jodit/blob/main/CHANGELOG.md)
- [Commits](xdan/jodit@4.16.0...4.17.1)

---
updated-dependencies:
- dependency-name: jodit
  dependency-version: 4.17.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file JavaScript Pull requests that update Javascript code labels Oct 8, 2026
@coderabbitai

coderabbitai Bot commented Oct 8, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 97848cb7-a5d7-4625-b6dd-33805cb7cb13

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file JavaScript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants