Skip to content

chore(deps): update dependency solid-js to v1.9.4 [security] - #66

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-solid-js-vulnerability
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-solid-js-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Feb 25, 2025 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
solid-js (source) 1.8.18 → 1.9.4 age confidence

Solid Lacks Escaping of HTML in JSX Fragments allows for Cross-Site Scripting (XSS)

CVE-2025-27109 / GHSA-3qxh-p7jc-5xh6

More information

Details

Inserts/JSX expressions inside illegal inlined JSX fragments lacked escaping, allowing user input to be rendered as HTML when put directly inside JSX fragments.

For instance, ?text=<svg/onload=alert(1)> would trigger XSS here.

  const [text] = createResource(() => {
    return new URL(getRequestEvent().request.url).searchParams.get("text");
  });

  return (
    <>
      Text: {text()}
    </>
  );

Severity

  • CVSS Score: 7.3 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

solidjs/solid (solid-js)

v1.9.4

Compare Source

v1.9.3

Compare Source

v1.9.2

v1.9.0: - LGTM!

Compare Source

This release like the last is focusing on small quality of life improvements and adjustments that will help us move towards 2.0. So while not the most exciting release to everyone it provides some really important features and fixes to some developers.

And unlike many previous releases the vast majority of the work and features came from PRs from the community. So really all I can say is Looks Good to Me!

Better JSX Validation

While still incomplete across templates we've added JSDOM to the compiler to better detect invalid HTML at build time by comparing what we expect the template to be with what a browser would output. This now includes things that are nested we didn't detect before like putting <a> inside other <a> tags which will lead to the browser "correcting" it in less than intuitive ways.

Improved Exports

While each environment in solid-js/web has its own methods to be used in the compiler. We are now exporting the client methods from the server to prevent weird import errors. Now these methods will throw if used in this environment but shouldn't break your build.

Additionally we have seen some issues in bundlers that incorrectly feed our ESM exports back through the browser field. While this is a known issue they all pointed issues at each other and with no intention of fixing it. We have removed the browser field in this release, meaning some legacy packages may have issues resolving browser if they don't support export conditions.

This is regretful but this blocked deployments on several platforms and since this was the only fix at our disposal after two years of attempting to push this issue to the bundlers to no avail, we've moved forward with it.

Custom Element improvements

We have a few improvements to our custom element support in this release. First off we now detect elements with the is attribute as custom elements which means all the special behavior is afforded to them.

We've also improved our event handler delegating retargetting to better handle shadow DOM events. There were cases where we skipped over part of the tree.

Finally we've added the bool: attribute namespace to handle explicitly setting certain attributes according to boolean attribute rules. While this isn't necessary for built-in booleans currently we handle most attributes as properties and we lacked a specific override. But now we have it:

<my-element bool:enable={isEnabled()}></my-element>

Support for handleEvent Syntax in Non-Delegated Events

A little known thing is that events actually also support objects instead of functions (See: https://developer.mozilla.org/en-US/docs/Web/API/EventTarget/addEventListener)

We(thanks @​titoBouzout) realized we can use this mechanism as a way to set advanced rules like passive or capture on this object as way to handle all current and future event attributes that browsers might add. This way we don't need specific mechanisms like oncapture: (which is now deprecated).

Instead using on: you can set the event properties you wish.

<>
  <div on:click={{
    handleEvent(e) {
      console.log("clicked", e)
    },
    once:true
  }/>
  <div on:wheel={{
    handleEvent(e) {
      e.preventDefault() // only works on not passive events
      e.stopPropagation()  
      console.log("wheel stopped?")
    },
    passive: false
  }} />
</>

Other Updates

We've fixed an issue with lazy images. Apparently, cloneNode doesn't handle them properly so we've updated our heuristic to treat templates with lazy images to be handled with importNode.

We've improved our Hydration Mismatch Error to output the template of that it can't find the matching ID for. This should make it easier to track down where the hydration errors are occurring. There have been several hydration improvements over the later 1.8 releases so upgrading will likely improve the situation for those who have been facing issues.

Finally, we've improved some of the types in the JSX and Signal Setter in this release.


Big thanks to those who contributed to this release: @​wkelly17, @​olivercoad, @​titoBouzout, @​trusktr, @​Huliiiiii. And thanks to all of you who gave feedback on the Metadata/Head Tag RFC. While it didn't make it in this time around you've definitely given us stuff to consider for its future design.

Best,
@​ryansolid

v1.8.23

Compare Source

v1.8.22

Compare Source

v1.8.21

Compare Source

v1.8.20

Compare Source

v1.8.19

Compare Source


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@coderabbitai

coderabbitai Bot commented Feb 25, 2025 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 0f0cd31d-ab00-4dbc-97a6-4cbeb5c55f44

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown

Visit the preview URL for this PR (updated for commit d60ae98):

https://autonomy-tegata-dev--pr66-renovate-npm-solid-j-77gvue7e.web.app

(expires Tue, 04 Mar 2025 22:57:53 GMT)

🔥 via Firebase Hosting GitHub Action 🌎

Sign: 372cb972329a2dd7e3813bc6bde2f0d317d6488e

@renovate
renovate Bot force-pushed the renovate/npm-solid-js-vulnerability branch from d60ae98 to 282a206 Compare May 19, 2025 20:10
@renovate
renovate Bot force-pushed the renovate/npm-solid-js-vulnerability branch from 282a206 to 26434a1 Compare May 28, 2025 07:10
@renovate
renovate Bot force-pushed the renovate/npm-solid-js-vulnerability branch from 26434a1 to f9ca2d8 Compare September 25, 2025 20:37
@renovate renovate Bot changed the title fix(deps): update dependency solid-js to v1.9.4 [security] chore(deps): update dependency solid-js to v1.9.4 [security] Sep 25, 2025
@renovate
renovate Bot force-pushed the renovate/npm-solid-js-vulnerability branch from f9ca2d8 to c909539 Compare November 18, 2025 11:56
@renovate
renovate Bot force-pushed the renovate/npm-solid-js-vulnerability branch from c909539 to 69a7c97 Compare December 31, 2025 12:34
@renovate
renovate Bot force-pushed the renovate/npm-solid-js-vulnerability branch from 69a7c97 to c41e17d Compare January 23, 2026 19:03
@renovate
renovate Bot force-pushed the renovate/npm-solid-js-vulnerability branch from c41e17d to 1d364da Compare February 12, 2026 16:05
@renovate
renovate Bot force-pushed the renovate/npm-solid-js-vulnerability branch from 1d364da to b76554a Compare March 13, 2026 10:32
@renovate renovate Bot changed the title chore(deps): update dependency solid-js to v1.9.4 [security] chore(deps): update dependency solid-js to v1.9.4 [security] - autoclosed Mar 27, 2026
@renovate renovate Bot closed this Mar 27, 2026
@renovate
renovate Bot deleted the renovate/npm-solid-js-vulnerability branch March 27, 2026 00:55
@renovate renovate Bot changed the title chore(deps): update dependency solid-js to v1.9.4 [security] - autoclosed chore(deps): update dependency solid-js to v1.9.4 [security] Mar 30, 2026
@renovate renovate Bot reopened this Mar 30, 2026
@renovate
renovate Bot force-pushed the renovate/npm-solid-js-vulnerability branch 2 times, most recently from b76554a to 59e60f3 Compare March 30, 2026 22:07
@renovate
renovate Bot force-pushed the renovate/npm-solid-js-vulnerability branch from 59e60f3 to c1d10c1 Compare April 8, 2026 17:11
@renovate renovate Bot changed the title chore(deps): update dependency solid-js to v1.9.4 [security] chore(deps): update dependency solid-js to v1.9.4 [security] - autoclosed Apr 27, 2026
@renovate renovate Bot closed this Apr 27, 2026
@renovate renovate Bot changed the title chore(deps): update dependency solid-js to v1.9.4 [security] - autoclosed chore(deps): update dependency solid-js to v1.9.4 [security] Apr 27, 2026
@renovate renovate Bot reopened this Apr 27, 2026
@renovate
renovate Bot force-pushed the renovate/npm-solid-js-vulnerability branch 2 times, most recently from c1d10c1 to 7de748c Compare April 27, 2026 21:42
@renovate
renovate Bot force-pushed the renovate/npm-solid-js-vulnerability branch from 7de748c to 118febd Compare May 12, 2026 11:44
@renovate
renovate Bot force-pushed the renovate/npm-solid-js-vulnerability branch from 118febd to 8bcd40e Compare July 12, 2026 17:43
@renovate
renovate Bot force-pushed the renovate/npm-solid-js-vulnerability branch from 8bcd40e to 62b207e Compare July 21, 2026 00:14
@renovate
renovate Bot force-pushed the renovate/npm-solid-js-vulnerability branch from 62b207e to 8604323 Compare July 30, 2026 17:45
@renovate
renovate Bot force-pushed the renovate/npm-solid-js-vulnerability branch from 8604323 to a8b2624 Compare August 11, 2026 23:26
@renovate
renovate Bot force-pushed the renovate/npm-solid-js-vulnerability branch from a8b2624 to af11c58 Compare August 26, 2026 17:02
@renovate
renovate Bot force-pushed the renovate/npm-solid-js-vulnerability branch 2 times, most recently from 4ae51ec to f4edc10 Compare September 9, 2026 16:11
@renovate
renovate Bot force-pushed the renovate/npm-solid-js-vulnerability branch from f4edc10 to b08de37 Compare September 30, 2026 20:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants