Release Notes
Release notes
1.7.5 (NES) - December 2025
Dojo Notes
- This version includes the following security fixes:
- A high-severity Prototype Pollution vulnerability (CVE-2021-23450) in the
dojo.setObjectanddojo.getObjectfunctions. When user-controlled property paths containing__proto__orconstructorare processed, attackers can polluteObject.prototype, leading to property injection that can affect JavaScript objects.
- A high-severity Prototype Pollution vulnerability (CVE-2021-23450) in the
- Full package name and version:
@neverendingsupport/dojo@1.7.2-dojo-1.7.5
Dijit Notes
- This version includes the following security fixes:
- A medium-severity Cross-Site Scripting (XSS) vulnerability (CVE-2018-6561) in
dijit.Editorwhen using the ViewSource plugin. When users enter malicious HTML containing event handler attributes (such asonload,onclick,onerror) in source edit mode, attackers can inject arbitrary JavaScript that executes when the editor content is rendered or interacted with, leading to XSS attacks. - A low-severity Cross-Site Scripting (XSS) vulnerability (CVE-2020-4051) in the
dijit.EditorLinkDialog plugin. When user-controlled data containing unescaped HTML is entered in the linkdescriptionfield, attackers can inject arbitrary HTML tags and JavaScript event handlers, leading to XSS attacks.
- A medium-severity Cross-Site Scripting (XSS) vulnerability (CVE-2018-6561) in
- Full package name and version:
@neverendingsupport/dijit@1.7.2-dijit-1.7.5
Dojox Notes
- This version includes the following security fixes:
- A medium-severity Cross-site Scripting (XSS) vulnerability (CVE-2019-10785) that affects Dojox due to insufficient escape handling in
dojox.xmpp.util.xmlEncodeand related functions. Attackers could inject malicious scripts through unescaped user-supplied content in XML contexts, widget labels, and template attributes. - A low-severity Prototype Pollution vulnerability (CVE-2020-5259) affecting the Dojox jQuery wrapper. The
jqMixmethod allowed attackers to inject properties into JavaScript language construct prototypes by manipulating the special__proto__andconstructorproperties during object mixing operations, leading to property injection that can affect JavaScript objects.
- A medium-severity Cross-site Scripting (XSS) vulnerability (CVE-2019-10785) that affects Dojox due to insufficient escape handling in
- Full package name and version:
@neverendingsupport/dojox@1.7.2-dojox-1.7.5
1.7.4 (NES) - November 2025
Dojo Notes
- This release of
dojois to maintiain version synchronization across Dojo, Dijit, and Dojox packages. There are no functional changes in this release. - Full package name and version:
@neverendingsupport/dojo@1.7.2-dojo-1.7.4
Dijit Notes
- This release of
dijitis to maintiain version synchronization across Dojo, Dijit, and Dojox packages. There are no functional changes in this release. - Full package name and version:
@neverendingsupport/dijit@1.7.2-dijit-1.7.4
Dojox Notes
- This version includes the following security fixes:
- Fixes a critical-severity Cross-Site Scripting (XSS) vulnerability (CVE-2018-15494) in
dojox.grid.DataGrideditable cells. When user-controlled data containing unescaped double quotes is rendered in editable grid cells, attackers can inject arbitrary HTML attributes and JavaScript event handlers, leading to XSS attacks.
- Fixes a critical-severity Cross-Site Scripting (XSS) vulnerability (CVE-2018-15494) in
- Full package name and version:
@neverendingsupport/dojox@1.7.2-dojox-1.7.4
1.7.3 (NES) - October 2025
Dojo Notes
- This release originates from the open-source dojo repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful building. This release contains no functional changes from dojo 1.7.2.
- Full package name and version:
@neverendingsupport/dojo@1.7.2-dojo-1.7.3
Dijit Notes
- This release originates from the open-source dijit repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful building. This release contains no functional changes from dijit 1.7.2.
- Full package name and version:
@neverendingsupport/dijit@1.7.2-dijit-1.7.3
Dojox Notes
- This release originates from the open-source dojox repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful building. This release contains no functional changes from dojox 1.7.2.
- Full package name and version:
@neverendingsupport/dojox@1.7.2-dojox-1.7.3