Packages
| Package | Version |
|---|---|
@egjs/flicking
| 4.17.1 |
@egjs/react-flicking
| 4.17.1 |
@egjs/vue3-flicking
| 4.17.1 |
Highlights
- Fixed a mutation-XSS (mXSS) vulnerability in panel serialization —
CrossFlickingandFlicking#setStatusused to round-trip panel content throughinnerHTML/outerHTMLstrings, which could revive a payload that was inert on first render.CrossFlickingnow builds its structure only throughcloneNode/appendChild, andsetStatusparses the storedhtmlinertly and strips script-capable content (<script>,<iframe>,on*handlers,javascript:URLs) before restoring panels. Upgrading is recommended for every app that callssetStatuswith untrusted content or usesCrossFlicking. (#960) - React Strict Mode compatibility via dependency updates —
@egjs/axesis bumped to^3.9.3and@egjs/react-flickingnow depends on@cfcs/react^0.1.1, picking up the fixes needed to run cleanly under React Strict Mode's double-invocation. (#963)
Note:
setStatusnow sanitizes thehtmlit restores. If you relied on restoring panels that contain inline event handlers or script-capable elements throughsetStatus, those attributes/elements are stripped as of this version.
What's Changed
- chore: node 삭제, react strict mode 대응한 모듈 업데이트 by @daybrush in #963
- feat(release): 머지 후 publish 순서 도입 & /release 스킬 추가 by @cjw783 in #961
- fix(release): bump 인자 제거, 3단계 버전 확인 상시화 by @cjw783 in #967
- fix: use cloneNode instead of innerHTML by @malangfox in #960
Full Changelog: 4.17.0...4.17.1