github pluk-inc/markdown-preview v0.0.22
Markdown Preview 0.0.22

latest releases: v0.0.49, v0.0.48, v0.0.47...
3 months ago

Markdown Preview now sanitizes rendered HTML before it reaches the preview WebView, and Sparkle update checks point at the Amore-published appcast.

Changed

  • Amore sponsor credit added. The README now lists Amore among the project sponsors (#105).

Fixed

  • Sparkle feed URL now matches Amore hosting. Update checks now use the Amore appcast path at https://release.md-preview.app/v1/apps/doc.md-preview/appcast.xml, so installed copies look at the feed that Amore publishes.

Security

  • Rendered Markdown HTML is sanitized with DOMPurify. The app and Quick Look extension now route generated article HTML through DOMPurify before inserting it into the WebView, blocking inline event handlers, executable tags, dangerous URL schemes, hidden style-based copy substitutions, and related raw-HTML injection attacks while preserving Markdown rendering, KaTeX, Mermaid, highlight.js, local images, links, task lists, footnotes, code copy buttons, find, scrollspy, and heading IDs (#104).

Contributors

Thanks to the external contributors who shipped in this release:

Don't miss a new markdown-preview release

NewReleases is sending notifications on new releases.