Bugfix
- [security] Updated the bundled DOM sanitizer from 1.0.11 to 1.0.18, bringing the fixes from the 2.x line for sanitized SVG and HTML: CSS comments, escapes, line continuations and
image-set()can no longer hide external resource references in stylesheets,styleattributes or SVG presentation attributes;javascript:and non-imagedata:URLs are rejected in every URL attribute, not onlyhref; and XML processing instructions and SVG animations can no longer bring back markup or links the sanitizer removed (GHSA-jfrr-ch68-f2w9, GHSA-ww22-4mqv-x5w3, GHSA-wcj2-r6vg-rm97, GHSA-mrpv-6x26-mf6c, GHSA-cjfg-j8jp-5xvc, GHSA-4hr3-f334-mcr4, GHSA-7x4f-fj83-6xfw, GHSA-94fv-h7hv-365q) - [security] With image URL actions turned on, the image pixel limit now measures the image each resize actually produces, including one-dimension, percentage and zoomCrop resizes. Backport of the Grav 2.2.2 fix. Thanks @manus-pi