dependabot[bot] and objecttothis
9e06a231a7
chore(deps): bump brace-expansion ( #4721 )
...
Bumps and [brace-expansion](https://github.com/juliangruber/brace-expansion ). These dependencies needed to be updated together.
Updates `brace-expansion` from 1.1.18 to 1.1.21
- [Release notes](https://github.com/juliangruber/brace-expansion/releases )
- [Commits](https://github.com/juliangruber/brace-expansion/compare/v1.1.18...v1.1.21 )
Updates `brace-expansion` from 2.1.4 to 2.1.7
- [Release notes](https://github.com/juliangruber/brace-expansion/releases )
- [Commits](https://github.com/juliangruber/brace-expansion/compare/v1.1.18...v1.1.21 )
---
updated-dependencies:
- dependency-name: brace-expansion
dependency-version: 1.1.21
dependency-type: indirect
- dependency-name: brace-expansion
dependency-version: 2.1.7
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: objecttothis <17935339+objecttothis@users.noreply.github.com >
2026-10-02 14:34:32 +04:00
dependabot[bot] and objecttothis
90feb434eb
chore(deps): bump moment from 2.30.1 to 2.31.0 ( #4722 )
...
Bumps [moment](https://github.com/moment/moment ) from 2.30.1 to 2.31.0.
- [Release notes](https://github.com/moment/moment/releases )
- [Changelog](https://github.com/moment/moment/blob/develop/CHANGELOG.md )
- [Commits](https://github.com/moment/moment/compare/2.30.1...2.31.0 )
---
updated-dependencies:
- dependency-name: moment
dependency-version: 2.31.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: objecttothis <17935339+objecttothis@users.noreply.github.com >
2026-10-02 14:18:33 +04:00
dependabot[bot]
fd3d642a8e
chore(deps): bump dompurify from 3.4.13 to 3.4.16 ( #4723 )
...
Bumps [dompurify](https://github.com/cure53/DOMPurify ) from 3.4.13 to 3.4.16.
- [Release notes](https://github.com/cure53/DOMPurify/releases )
- [Commits](https://github.com/cure53/DOMPurify/compare/3.4.13...3.4.16 )
---
updated-dependencies:
- dependency-name: dompurify
dependency-version: 3.4.16
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 20:11:07 +02:00
github-actions[bot]
89c6d5a3e9
chore: bump version to 3.4.3
2026-09-30 16:27:25 +00:00
jekkos
7aa624c8ea
chore: reset 3.4.2 (undo premature 3.4.3 bump + stale changelog) for re-cut
2026-09-30 16:23:17 +00:00
jekkos
9cafea0eed
fix(release): keep package-lock.json version in sync on bump ( #4718 )
...
* fix(release): keep package-lock.json version in sync on bump
The release bump step updated app/Config/App.php and package.json but
left package-lock.json on the old version, so the lockfile drifted out
of sync with package.json on every release. Bump the @opensourcepos/
opensourcepos package version in package-lock.json (top-level and
packages."") using the same scoped approach, and stage it in the bump
commit.
Fixes #4717
* fix(release): sync package-lock.json to 3.4.3 on master
Bump the @opensourcepos/opensourcepos version in package-lock.json
(top-level + packages."") from 3.4.2 to 3.4.3 to match package.json,
which was already bumped during the 3.4.3 dev bump. This repairs the
current drift introduced by the bump commit so the upcoming 3.4.3
release ships with package.json and package-lock.json in sync.
Part of #4717
2026-09-29 13:16:18 +02:00
dependabot[bot] and objecttothis
d821cf8d3a
chore(deps): bump fflate from 0.8.2 to 0.8.3 ( #4690 )
...
Bumps [fflate](https://github.com/101arrowz/fflate ) from 0.8.2 to 0.8.3.
- [Release notes](https://github.com/101arrowz/fflate/releases )
- [Changelog](https://github.com/101arrowz/fflate/blob/master/CHANGELOG.md )
- [Commits](https://github.com/101arrowz/fflate/compare/v0.8.2...v0.8.3 )
---
updated-dependencies:
- dependency-name: fflate
dependency-version: 0.8.3
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: objecttothis <17935339+objecttothis@users.noreply.github.com >
2026-09-23 13:40:35 +04:00
objecttothis
6a36cdc3e9
fix(licenses): guard malformed data, parallelize gulp tasks, require Node 20
...
fix(config): guard against non-array and incomplete license data
- Wrap npm-prod/npm-dev license parsing in is_array() checks to avoid
foreach errors when JSON decodes to null or non-array
- Skip dependency entries missing required keys (name, author, homepage,
installedVersion, licenseType) in open-source and license-key loops
fix(gulp): correctly await all async tasks
- Parallelize update-licenses, copy-bootswatch, copy-bootswatch5, and
copy-bootstrap sub-tasks via Promise.all
- Wrap exec() calls with finished(execStream.resume()) so composer and
npm license-report commands fully write output files before task resolves;
.resume() drains stdout so streams can emit close/finish events
build(package): require Node.js >=20
- Add engines field to package.json
- Regenerate package-lock.json with matching constraint
- Document prerequisite in BUILD.md; license-reporting dep needs regex
features unavailable in Node 18 and earlier
Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com >
2026-09-10 17:32:52 +04:00
dependabot[bot]
65b99fea97
chore(deps): bump dompurify from 3.4.12 to 3.4.13 ( #4639 )
...
Bumps [dompurify](https://github.com/cure53/DOMPurify ) from 3.4.12 to 3.4.13.
- [Release notes](https://github.com/cure53/DOMPurify/releases )
- [Commits](https://github.com/cure53/DOMPurify/compare/3.4.12...3.4.13 )
---
updated-dependencies:
- dependency-name: dompurify
dependency-version: 3.4.13
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-10 21:42:43 +04:00
objecttothis and Travis Garrison
8e465f9256
chore(deps): bump lodash.template from 4.5.0 to 4.18.1 ( #4616 )
...
Signed-off-by: Travis Garrison <travis@chiraqbookstore.com >
Co-authored-by: Travis Garrison <travis@chiraqbookstore.com >
2026-08-04 17:58:50 +04:00
objecttothis and Travis Garrison
734c7d291c
chore(deps): add xlsx via SheetJS CDN and upgrade tableexport plugin ( #4615 )
...
- Add xlsx 0.20.3 from SheetJS CDN via package overrides
- Bump tableexport.jquery.plugin from ^1.30.0 to ^1.33.0
- Add xlsx bundle to gulp JS pipeline before tableexport
Signed-off-by: Travis Garrison <travis@chiraqbookstore.com >
Co-authored-by: Travis Garrison <travis@chiraqbookstore.com >
2026-08-04 17:57:41 +04:00
dependabot[bot]
337cc098f2
chore(deps): bump brace-expansion ( #4614 )
...
Bumps and [brace-expansion](https://github.com/juliangruber/brace-expansion ). These dependencies needed to be updated together.
Updates `brace-expansion` from 1.1.12 to 1.1.18
- [Release notes](https://github.com/juliangruber/brace-expansion/releases )
- [Commits](https://github.com/juliangruber/brace-expansion/compare/v1.1.12...v1.1.18 )
Updates `brace-expansion` from 2.1.0 to 2.1.4
- [Release notes](https://github.com/juliangruber/brace-expansion/releases )
- [Commits](https://github.com/juliangruber/brace-expansion/compare/v1.1.12...v1.1.18 )
---
updated-dependencies:
- dependency-name: brace-expansion
dependency-version: 1.1.18
dependency-type: indirect
- dependency-name: brace-expansion
dependency-version: 2.1.4
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-04 17:15:13 +04:00
dependabot[bot]
0107524f71
chore(deps): bump dompurify from 3.4.11 to 3.4.12 ( #4602 )
...
Bumps [dompurify](https://github.com/cure53/DOMPurify ) from 3.4.11 to 3.4.12.
- [Release notes](https://github.com/cure53/DOMPurify/releases )
- [Commits](https://github.com/cure53/DOMPurify/compare/3.4.11...3.4.12 )
---
updated-dependencies:
- dependency-name: dompurify
dependency-version: 3.4.12
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-28 14:22:36 +04:00
dependabot[bot] and objecttothis
632d4eacce
chore(deps): bump dompurify from 3.4.0 to 3.4.11 ( #4578 )
...
Bumps [dompurify](https://github.com/cure53/DOMPurify ) from 3.4.0 to 3.4.11.
- [Release notes](https://github.com/cure53/DOMPurify/releases )
- [Commits](https://github.com/cure53/DOMPurify/compare/3.4.0...3.4.11 )
---
updated-dependencies:
- dependency-name: dompurify
dependency-version: 3.4.11
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: objecttothis <17935339+objecttothis@users.noreply.github.com >
2026-06-26 16:45:30 +04:00
dependabot[bot]
144e73eba6
chore(deps): bump minimatch from 3.1.2 to 3.1.5 ( #4536 )
...
Bumps [minimatch](https://github.com/isaacs/minimatch ) from 3.1.2 to 3.1.5.
- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md )
- [Commits](https://github.com/isaacs/minimatch/compare/v3.1.2...v3.1.5 )
---
updated-dependencies:
- dependency-name: minimatch
dependency-version: 3.1.5
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-08 16:49:39 +04:00
BudsieBuds
42ba39d290
chore: miscellaneous updates and improvements ( #4530 )
...
- reinstated 'update-licenses' task in gulp (accidentally removed in 3e844f2f89 )
- updated bootstrap, bootswatch, and various dev dependencies
- refinded text across UI
- applied consistency fixes
- added 'number' and 'tel' input types to relevant settings
- improved system info layout (still room for improvement, but better)
- updated and fixed changelog
2026-05-08 09:07:52 +02:00
dependabot[bot]
b6f28da058
Bump dompurify from 3.3.2 to 3.4.0 ( #4512 )
...
Bumps [dompurify](https://github.com/cure53/DOMPurify ) from 3.3.2 to 3.4.0.
- [Release notes](https://github.com/cure53/DOMPurify/releases )
- [Commits](https://github.com/cure53/DOMPurify/compare/3.3.2...3.4.0 )
---
updated-dependencies:
- dependency-name: dompurify
dependency-version: 3.4.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-16 14:14:29 +04:00
dependabot[bot] and objecttothis
609b206375
Bump lodash from 4.17.23 to 4.18.1 ( #4462 )
...
Bumps [lodash](https://github.com/lodash/lodash ) from 4.17.23 to 4.18.1.
- [Release notes](https://github.com/lodash/lodash/releases )
- [Commits](https://github.com/lodash/lodash/compare/4.17.23...4.18.1 )
---
updated-dependencies:
- dependency-name: lodash
dependency-version: 4.18.1
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: objecttothis <17935339+objecttothis@users.noreply.github.com >
2026-04-14 01:21:43 +04:00
dependabot[bot] and objecttothis
e046e74c79
Bump picomatch from 2.3.1 to 2.3.2 ( #4451 )
...
Bumps [picomatch](https://github.com/micromatch/picomatch ) from 2.3.1 to 2.3.2.
- [Release notes](https://github.com/micromatch/picomatch/releases )
- [Changelog](https://github.com/micromatch/picomatch/blob/master/CHANGELOG.md )
- [Commits](https://github.com/micromatch/picomatch/compare/2.3.1...2.3.2 )
---
updated-dependencies:
- dependency-name: picomatch
dependency-version: 2.3.2
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: objecttothis <17935339+objecttothis@users.noreply.github.com >
2026-03-30 12:38:07 +04:00
dependabot[bot]
e4b92b58c3
Bump jspdf from 4.2.0 to 4.2.1
...
Bumps [jspdf](https://github.com/parallax/jsPDF ) from 4.2.0 to 4.2.1.
- [Release notes](https://github.com/parallax/jsPDF/releases )
- [Changelog](https://github.com/parallax/jsPDF/blob/master/RELEASE.md )
- [Commits](https://github.com/parallax/jsPDF/compare/v4.2.0...v4.2.1 )
---
updated-dependencies:
- dependency-name: jspdf
dependency-version: 4.2.1
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-17 19:06:05 +00:00
dependabot[bot] and objecttothis
85889b6e65
Bump jspdf from 4.1.0 to 4.2.0 ( #4383 )
...
Bumps [jspdf](https://github.com/parallax/jsPDF ) from 4.1.0 to 4.2.0.
- [Release notes](https://github.com/parallax/jsPDF/releases )
- [Changelog](https://github.com/parallax/jsPDF/blob/master/RELEASE.md )
- [Commits](https://github.com/parallax/jsPDF/compare/v4.1.0...v4.2.0 )
---
updated-dependencies:
- dependency-name: jspdf
dependency-version: 4.2.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: objecttothis <17935339+objecttothis@users.noreply.github.com >
2026-03-11 16:36:53 +04:00
dependabot[bot]
d6b767c80a
Bump dompurify from 3.3.1 to 3.3.2 ( #4402 )
...
Bumps [dompurify](https://github.com/cure53/DOMPurify ) from 3.3.1 to 3.3.2.
- [Release notes](https://github.com/cure53/DOMPurify/releases )
- [Commits](https://github.com/cure53/DOMPurify/compare/3.3.1...3.3.2 )
---
updated-dependencies:
- dependency-name: dompurify
dependency-version: 3.3.2
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-05 21:54:49 +01:00
dependabot[bot]
b23351a45c
Bump jspdf and jspdf-autotable ( #4373 )
...
Bumps [jspdf](https://github.com/parallax/jsPDF ) and [jspdf-autotable](https://github.com/simonbengtsson/jsPDF-AutoTable ). These dependencies needed to be updated together.
Updates `jspdf` from 3.0.2 to 4.1.0
- [Release notes](https://github.com/parallax/jsPDF/releases )
- [Changelog](https://github.com/parallax/jsPDF/blob/master/RELEASE.md )
- [Commits](https://github.com/parallax/jsPDF/compare/v3.0.2...v4.1.0 )
Updates `jspdf-autotable` from 5.0.2 to 5.0.7
- [Release notes](https://github.com/simonbengtsson/jsPDF-AutoTable/releases )
- [Commits](https://github.com/simonbengtsson/jsPDF-AutoTable/compare/v5.0.2...v5.0.7 )
---
updated-dependencies:
- dependency-name: jspdf
dependency-version: 4.1.0
dependency-type: direct:production
- dependency-name: jspdf-autotable
dependency-version: 5.0.7
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-07 11:46:11 +00:00
dependabot[bot]
bee0c8e364
Bump lodash from 4.17.21 to 4.17.23 ( #4369 )
...
Bumps [lodash](https://github.com/lodash/lodash ) from 4.17.21 to 4.17.23.
- [Release notes](https://github.com/lodash/lodash/releases )
- [Commits](https://github.com/lodash/lodash/compare/4.17.21...4.17.23 )
---
updated-dependencies:
- dependency-name: lodash
dependency-version: 4.17.23
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-01-22 20:51:03 +01:00
jekkos
3e844f2f89
Escape return_policy in receipt + invoice ( #4349 )
...
* Escape return_policy in receipt + invoice
* Enable CSRF using session token (#3632 )
2025-12-17 20:39:58 +01:00
jekkos
6dd5a9162f
Add DOMpurify + fix XSS ( #4341 )
2025-11-23 21:35:47 +01:00
jekkos
832db664e5
Fix tax configuration pages ( #4331 )
2025-11-21 22:13:35 +01:00
dependabot[bot]
4153c69ccd
Bump jspdf from 3.0.1 to 3.0.2 ( #4309 )
...
Bumps [jspdf](https://github.com/parallax/jsPDF ) from 3.0.1 to 3.0.2.
- [Release notes](https://github.com/parallax/jsPDF/releases )
- [Changelog](https://github.com/parallax/jsPDF/blob/master/RELEASE.md )
- [Commits](https://github.com/parallax/jsPDF/compare/v3.0.1...v3.0.2 )
---
updated-dependencies:
- dependency-name: jspdf
dependency-version: 3.0.2
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-08-29 07:32:54 +02:00
jekkos and El_Coloso
0d1f4efe3c
Extended payment delete fix ( #4274 )
...
* Create a Base64 URL-Safe encoding and decoding helper
* Rename web_helper to url_helper
---------
Co-authored-by: El_Coloso <diegoramosp@gmail.com >
2025-07-07 13:57:03 +02:00
BudsieBuds
2fec49e7df
Enhance license handling ( #4223 )
...
- automate license updates
- license text rendered in monospace font
- removed old bower license generation code
2025-04-19 20:20:50 +02:00
BudsieBuds
1bdc19f14f
Convert menu icons to SVG ( #4220 )
...
* Convert menu icons to SVG
- replaced png images with svg
- 20% decrease in file size, improving load times
- removed 384 unused files from repo
* Transferred package to organisation
2025-04-18 19:48:19 +02:00
BudsieBuds
fc37848fa7
Add default bootstrap to themes ( #4219 )
...
- also update bootstrap
2025-04-16 07:15:27 +02:00
dependabot[bot]
2c9ae36247
Bump jspdf and jspdf-autotable ( #4190 )
...
Bumps [jspdf](https://github.com/MrRio/jsPDF ) and [jspdf-autotable](https://github.com/simonbengtsson/jsPDF-AutoTable ). These dependencies needed to be updated together.
Updates `jspdf` from 2.5.1 to 3.0.1
- [Release notes](https://github.com/MrRio/jsPDF/releases )
- [Changelog](https://github.com/parallax/jsPDF/blob/master/RELEASE.md )
- [Commits](https://github.com/MrRio/jsPDF/compare/v2.5.1...v3.0.1 )
Updates `jspdf-autotable` from 3.8.2 to 5.0.2
- [Release notes](https://github.com/simonbengtsson/jsPDF-AutoTable/releases )
- [Commits](https://github.com/simonbengtsson/jsPDF-AutoTable/compare/v3.8.2...v5.0.2 )
---
updated-dependencies:
- dependency-name: jspdf
dependency-type: direct:production
- dependency-name: jspdf-autotable
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-31 13:03:50 +04:00
dependabot[bot]
69a507f879
Bump canvg from 3.0.10 to 3.0.11 ( #4189 )
...
Bumps [canvg](https://github.com/canvg/canvg ) from 3.0.10 to 3.0.11.
- [Release notes](https://github.com/canvg/canvg/releases )
- [Changelog](https://github.com/canvg/canvg/blob/v3.0.11/CHANGELOG.md )
- [Commits](https://github.com/canvg/canvg/commits/v3.0.11 )
---
updated-dependencies:
- dependency-name: canvg
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-31 11:40:49 +04:00
objecttothis
e90b5b87da
Replace tabs with spaces ( #4196 )
...
Signed-off-by: objecttothis <objecttothis@gmail.com >
2025-03-28 21:24:21 +04:00
BudsieBuds
beb18ff96b
Random fixes ( #4144 )
...
Random fixes in time for the 3.4.0 release.
- corrects typo in the items controller
- small update to login view
- removes deprecated code from header view
- ospos license updated to end 2024
- moved gulp packages to dev dependencies
- updated gulp-zip and npm-check-updates to latest version
- updated readme for consistency
- makes ospos license in config fully readable
- fixes composer libraries license view in config
- gulp now updates composer libraries license and ospos license
- updated other license views in config
2025-01-28 23:48:45 +01:00
objecttothis
28b8ff2ea6
Bump Bootstrap-table to 1.23.5
...
- This does not resolve #3854 but keeps the version up to date.
Signed-off-by: objecttothis <objecttothis@gmail.com >
2024-10-28 22:22:37 +01:00
dependabot[bot]
99530d64e0
Bump micromatch from 4.0.5 to 4.0.8 ( #4078 )
...
Bumps [micromatch](https://github.com/micromatch/micromatch ) from 4.0.5 to 4.0.8.
- [Release notes](https://github.com/micromatch/micromatch/releases )
- [Changelog](https://github.com/micromatch/micromatch/blob/master/CHANGELOG.md )
- [Commits](https://github.com/micromatch/micromatch/compare/4.0.5...4.0.8 )
---
updated-dependencies:
- dependency-name: micromatch
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-09-30 13:43:59 +04:00
dependabot[bot]
1662ef5856
Bump braces from 3.0.2 to 3.0.3 ( #4077 )
...
Bumps [braces](https://github.com/micromatch/braces ) from 3.0.2 to 3.0.3.
- [Changelog](https://github.com/micromatch/braces/blob/master/CHANGELOG.md )
- [Commits](https://github.com/micromatch/braces/compare/3.0.2...3.0.3 )
---
updated-dependencies:
- dependency-name: braces
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-09-30 13:43:17 +04:00
dependabot[bot]
07ee353113
Bump dompurify from 2.5.1 to 2.5.6 ( #4057 )
...
Bumps [dompurify](https://github.com/cure53/DOMPurify ) from 2.5.1 to 2.5.6.
- [Release notes](https://github.com/cure53/DOMPurify/releases )
- [Commits](https://github.com/cure53/DOMPurify/compare/2.5.1...2.5.6 )
---
updated-dependencies:
- dependency-name: dompurify
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-09-30 13:37:28 +04:00
jekkos and objecttothis
f49d763254
XSS mitigation features ( #4041 )
...
* Remove HtmlPurifier calls
- All calls to Services::htmlPurifier()->purify() removed from data received from view.
- Bootstrap and bootswatch bump in package-lock.json
Signed-off-by: objecttothis <objecttothis@gmail.com >
* Pre-view filtering Items Controller
- Refactored code for clarity
- Created and called sanitization functions.
- Sanitize TEXT type Attributes before being sent to the view.
Signed-off-by: objecttothis <objecttothis@gmail.com >
* Pre-view filtering Customers Controller
- Refactored code for clarity
- Replaced == with === operator to prevent type juggling
- Added Sanitization of Customer data before being sent to the view
Signed-off-by: objecttothis <objecttothis@gmail.com >
* Bump bootstrap-table to 1.23.1
- Bump bootstrap-table to 1.23.1 in attempt to resolve issue with sticky headers
- Sanitize attribute data in tables
- Sanitize item data with controller function.
Signed-off-by: objecttothis <objecttothis@gmail.com >
* Pre-view filtering Items Controller
- Refactored code for clarity
- Created and called sanitization functions.
- Sanitize TEXT type Attributes before being sent to the view.
Signed-off-by: objecttothis <objecttothis@gmail.com >
* Sanitize Item data
- Sanitize category and item_number before display in forms.
- refactor check in pic_filename for empty to be best practices compliant.
- Added TODO
Signed-off-by: objecttothis <objecttothis@gmail.com >
* Minor changes
- Refactored for code clarity.
- Removed extra blank lines.
- Minor reformatting.
- Added PHPdocs
- bumped bootstrap-table to 1.23.2
Signed-off-by: objecttothis <objecttothis@gmail.com >
* Pre-view filtering Items Controller
- Refactored code for clarity
- Created and called sanitization functions.
- Sanitize TEXT type Attributes before being sent to the view.
Signed-off-by: objecttothis <objecttothis@gmail.com >
* Sanitize Item data
- Sanitize category and item_number before display in forms.
- refactor check in pic_filename for empty to be best practices compliant.
- Added TODO
Signed-off-by: objecttothis <objecttothis@gmail.com >
---------
Signed-off-by: objecttothis <objecttothis@gmail.com >
Co-authored-by: objecttothis <objecttothis@gmail.com >
2024-08-26 11:35:56 +04:00
objecttothis
e1f8b73005
Add check to migration to prevent errors ( #4032 )
...
* Add check to migration
- Only drop the constraint if it exists.
Signed-off-by: objecttothis <objecttothis@gmail.com >
* Automatic bump of package-lock.json
Signed-off-by: objecttothis <objecttothis@gmail.com >
---------
Signed-off-by: objecttothis <objecttothis@gmail.com >
2024-07-27 00:08:49 +04:00
jekkos
8f52e283bb
Add gulp compress task ( #3916 )
2024-06-15 17:19:15 +02:00
jekkos
2fdddbc043
Revert gulp downgrade ( #3909 )
2024-06-15 17:19:15 +02:00
jekkos
75b00be637
Upgrade jspdf ( #3909 )
2024-06-15 17:19:15 +02:00
objecttothis
1bc3d141e9
Bump npm dependencies
...
- Revert jspdf and jspdf-autotable bump due to problems caused in npm run build
- Correct gulpfile for fixed reference.
- Reverted chartist dependency changes since it broke the build.
Signed-off-by: objecttothis <objecttothis@gmail.com >
2024-06-15 17:19:15 +02:00
objecttothis
2985b8c6ae
Bump npm dependencies
...
- Revert jspdf and jspdf-autotable bump due to problems caused in npm run build
- Correct gulpfile for fixed reference.
- Reverted chartist dependency changes since it broke the build.
Signed-off-by: objecttothis <objecttothis@gmail.com >
2024-06-15 17:19:15 +02:00
objecttothis
87b4526078
Bump npm dependencies
...
- bootstrap-tagsinput-2021 replaced bootstrap-tagsinput because the latter has vulnerabilities.
- Chartist and addons bumped to attempt to resolve issues with graphical reports.
- jspdf and addons bumped due to vulnerabilities. It's still be broken however.
Signed-off-by: objecttothis <objecttothis@gmail.com >
2024-06-15 17:19:15 +02:00
objecttothis
c1c2e9df77
Bumped bootstrap-table to 1.22.4
2024-06-15 17:19:15 +02:00
jekkos
fba33ed995
Update packaga-lock.json ( #3923 )
2024-06-15 17:19:15 +02:00