415301c
chore: cherry-pick 3fbd1dca6a4d from libvpx (#40024)b4742f9
feat: enable dark mode on GTK UIs (#40009)5868f9a
build: fix with enable_pdf_viewer = false
(#40000)6e675c8
chore: add deprecated app.runningUnderRosettaTranslation
to
breaking-change...66432ed
fix: use generic capturer to list both screens and windows when possible
(#39...0ed4837
chore: cherry-pick tls shutdown crash fix from upstream (#39945)42b4744
docs: add a more detailed explanation to cookies.flushStore() (#39905)04e85b4
ci: fix linux builds of forks (#39941)e42169b
fix: app.runningUnderARM64Translation()
always returning
true on Windows AR...67b2739
chore: cherry-pick 1 changes from Release-0-M117 (#39919)Sourced from sanitize-html's changelog.
2.12.1 (2024-02-22)
- Do not parse sourcemaps in
post-css
. This fixes a vulnerability in which information about the existence or non-existence of files on a server could be disclosed via properly crafted HTML input when thestyle
attribute is allowed by the configuration. Thanks to the Snyk Security team for the disclosure and to Dylan Armstrong for the fix.2.12.0 (2024-02-21)
Introduced the
allowedEmptyAttributes
option, enabling explicit specification of empty string values for select attributes, with the default attribute set toalt
. Thanks to Na for the contribution.Clarified the use of SVGs with a new test and changes to documentation. Thanks to Gauav Kumar for the contribution.
Do not process source maps when processing style tags with PostCSS.
4a7d7dd
Merge pull request #654
from apostrophecms/release-2.12.1f8e02be
release 2.12.1c5dbdf7
Merge pull request #650
from dylanarmstrong/fix/ignore-source-maps5a5a74e
Merge pull request #652
from apostrophecms/add-thanks-to-changelogee71ff0
Add community contribution thanks youa226fe7
Merge pull request #651
from apostrophecms/release-2.12.0ff18600
release 2.12.01e2294c
test: added test for postcss mapc376501
doc: update changelog075499d
fix: ignore source maps when processing with postcss