Skip to content

Add TinaCMS postMessage fix references#8280

Open
cookesan wants to merge 1 commit into
github:cookesan/advisory-improvement-8280from
cookesan:tinacms-g5qx-fix-references
Open

Add TinaCMS postMessage fix references#8280
cookesan wants to merge 1 commit into
github:cookesan/advisory-improvement-8280from
cookesan:tinacms-g5qx-fix-references

Conversation

@cookesan

Copy link
Copy Markdown

Adds the upstream merge commit and fixed package release references for GHSA-g5qx-h5f3-mp2f.

Evidence checked:

  • Harden message origin checks and rich-text URL sanitization tinacms/tinacms#7056 merged as c491fc55e612725f5d775eeb1fdf3f8ba82314fa.
  • The tinacms@3.9.3 and @tinacms/app@2.5.6 releases both include that merge commit and list the security hardening PR.
  • npm package archives for tinacms 3.9.2/3.9.3 and @tinacms/app 2.5.5/2.5.6 match registry shasums; the fixed archives include origin/source checks for the admin and preview postMessage flows, plus exact target origins for preview messages.

@github-actions github-actions Bot changed the base branch from main to cookesan/advisory-improvement-8280 June 29, 2026 12:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant