+2
-3
| { | ||
| "packageManager": "yarn@2.4.3", | ||
| "name": "svgo", | ||
| "version": "2.8.2", | ||
| "version": "2.8.3", | ||
| "description": "Nodejs-based tool for optimizing SVG vector graphics files", | ||
@@ -49,4 +49,3 @@ "license": "MIT", | ||
| "plugins", | ||
| "dist", | ||
| "!**/*.test.js" | ||
| "dist" | ||
| ], | ||
@@ -53,0 +52,0 @@ "engines": { |
@@ -10,3 +10,34 @@ 'use strict'; | ||
| /** Namespaces that support executable <script> elements. */ | ||
| const SCRIPT_NAMESPACES = [ | ||
| 'http://www.w3.org/2000/svg', | ||
| 'http://www.w3.org/1999/xhtml', | ||
| ]; | ||
| /** | ||
| * @param {string} elem | ||
| * @param {string} targetElem | ||
| * @param {ReadonlyMap<string, string[]>} prefixes | ||
| * @param {string[]} targetNamespaces | ||
| * @returns {boolean} | ||
| */ | ||
| function isNamespaceAwareElem(elem, targetElem, prefixes, targetNamespaces) { | ||
| if (elem === targetElem) { | ||
| return true; | ||
| } | ||
| if (elem.includes(':')) { | ||
| const [prefix, effectiveTag] = elem.split(':', 2); | ||
| if (targetElem === effectiveTag) { | ||
| const namespaces = /** @type {string[]} */ (prefixes.get(prefix)); | ||
| const namespace = namespaces[namespaces.length - 1]; | ||
| return targetNamespaces.includes(namespace); | ||
| } | ||
| } | ||
| return false; | ||
| } | ||
| /** | ||
| * Remove <script>. | ||
@@ -21,11 +52,45 @@ * | ||
| exports.fn = () => { | ||
| /** | ||
| * Map of XML namespace prefixes to the XML namespace. Each value is a stack | ||
| * as XML namespaces can be pushed to in children elements and revert back | ||
| * previous namespace when we exit that node. | ||
| * | ||
| * @type {Map<string, string[]>} */ | ||
| const prefixes = new Map(); | ||
| return { | ||
| element: { | ||
| enter: (node, parentNode) => { | ||
| if (node.name === 'script') { | ||
| for (const [k, v] of Object.entries(node.attributes)) { | ||
| if (!k.startsWith('xmlns:')) { | ||
| continue; | ||
| } | ||
| const prefix = k.slice(6); | ||
| if (!prefixes.has(prefix)) { | ||
| prefixes.set(prefix, [v]); | ||
| } else { | ||
| /** @type {string[]} */ (prefixes.get(prefix)).push(v); | ||
| } | ||
| } | ||
| if ( | ||
| isNamespaceAwareElem(node.name, 'script', prefixes, SCRIPT_NAMESPACES) | ||
| ) { | ||
| detachNodeFromParent(node, parentNode); | ||
| } | ||
| }, | ||
| exit: (node) => { | ||
| for (const k of Object.keys(node.attributes)) { | ||
| if (!k.startsWith('xmlns:')) { | ||
| continue; | ||
| } | ||
| const prefix = k.slice(6); | ||
| /** @type {string[]} */ (prefixes.get(prefix)).pop(); | ||
| } | ||
| }, | ||
| }, | ||
| }; | ||
| }; |
Sorry, the diff of this file is too big to display
URL strings
Supply chain riskPackage contains fragments of external URLs or IP addresses, which the package may be accessing at runtime.
URL strings
Supply chain riskPackage contains fragments of external URLs or IP addresses, which the package may be accessing at runtime.
979889
0.27%15241
0.38%