- Fixed a possible security problem when
SAFE_FOR_TEMPLATES
istrue
(default isfalse
), thanks @masatokinugawa - Fixed a security problem when
ALLOWED_TAGS
orADD_TAGS
white-listsnoembed
ornoscript
(not the default), thanks @masatokinugawa - Added better internal code hardening, thanks @choumx
- Extended the SVG attribute whitelist
- Added more tests
- Added better browser coverage for CI via BrowserStack
- Cleaned up legacy browser coverage for CI via BrowserStack