Skip to content

chore(deps): bump ammonia from 4.1.2 to 4.2.1 in /czech-file-knife - #388

Merged
hyperpolymath merged 3 commits into
mainfrom
dependabot/cargo/czech-file-knife/ammonia-4.2.1
Oct 8, 2026
Merged

hyperpolymath merged 3 commits into
mainfrom
dependabot/cargo/czech-file-knife/ammonia-4.2.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps ammonia from 4.1.2 to 4.2.1.

Release notes

Sourced from ammonia's releases.

4.2.1

  • fix: apply URL rewrites to CSS url() function
  • Security fix: CSS sanitization only ever worked on attributes, not stylesheets. This now panics if you try to enable the style tag while also using style attribute filtering

4.1.5

  • fix: apply URL rewrites to CSS url() function
  • Security fix: CSS sanitization only ever worked on attributes, not stylesheets. This now panics if you try to enable the style tag while also using style attribute filtering

4.2.0

  • chore: upgrade to html5ever 0.40.0
  • chore: upgrade to cssparser 0.38.0
  • chore: bump MSRV to 1.85.0
  • feat: add introspection methods for relative url settings to Builder (@​gghez)
  • Security fixes are not backported to 4.0 any more. Only 3.3, 4.1, and 4.2 are supported.

4.1.4

  • fix: SVG animation and set can cause XSS, because attributeName is not checked (reported by Younghun Ko, koyokr)

4.1.3

  • fix: unexpected namespace switches after cleanup on MathML annotation-xml can cause mXSS

Special thanks to Ivan Ivančić (ivan0912, YesWeHack) for finding this vulnerability!

Changelog

Sourced from ammonia's changelog.

4.2.1

  • fix: apply URL rewrites to CSS url() function
  • Security fix: CSS sanitization only ever worked on attributes, not stylesheets. This now panics if you try to enable the style tag while also using style attribute filtering

4.2.0

  • chore: upgrade to [html5ever 0.40.0][]
  • chore: upgrade to cssparser 0.38.0
  • chore: bump MSRV to 1.85.0
  • feat: add introspection methods for relative url settings to Builder (@​gghez)
  • Security fixes are not backported to 4.0 any more. Only 3.3, 4.1, and 4.2 are supported.

4.1.4

  • fix: SVG animation and set can cause XSS, because attributeName is not checked (reported by Younghun Ko, koyokr)

4.1.3

  • fix: unexpected namespace switches after cleanup on MathML annotation-xml can cause mXSS (reported by Ivan Ivančić)

  • chore: upgrade to html5ever 0.37.1

  • chore: always strip the contents of selectedcontent elements, since the parser will always replace it with the actual contents anyway

Commits
  • 6013920 Merge pull request #258 from rust-ammonia/release-4.2.1
  • 8de5554 Release 4.2.1
  • 30d269b Merge pull request #256 from rust-ammonia/url-in-css
  • 406ba91 Prevent footgun around style filtering
  • 0239fea Fix handling of URLs in CSS background
  • 4c7a852 Merge pull request #254 from rust-ammonia/release-4.2
  • 6734bc7 Update security policy
  • b058406 Add changelog entry for gghez's PR 240
  • 6bb0458 Merge pull request #253 from rust-ammonia/dependabot/cargo/cssparser-0.38.0
  • 0201004 Merge pull request #240 from gghez/worktree-issue-128-expose-base-url
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [ammonia](https://github.com/rust-ammonia/ammonia) from 4.1.2 to 4.2.1.
- [Release notes](https://github.com/rust-ammonia/ammonia/releases)
- [Changelog](https://github.com/rust-ammonia/ammonia/blob/master/CHANGELOG.md)
- [Commits](rust-ammonia/ammonia@v4.1.2...v4.2.1)

---
updated-dependencies:
- dependency-name: ammonia
  dependency-version: 4.2.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Oct 5, 2026
@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: f0fd4444-79ef-4732-aa96-49be51504348

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit 70f4e1b into main Oct 8, 2026
16 of 19 checks passed
@hyperpolymath
hyperpolymath deleted the dependabot/cargo/czech-file-knife/ammonia-4.2.1 branch October 8, 2026 17:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant