- security: fix an XSS-filter bypass where an evil tag followed by a tab, CR, LF or FF instead of a space (e.g.
<style\t>,<svg\n>,<math\r>,<frameset\f>) was emitted unencoded. A raw<style>stayed open (its closing tag is encoded) and allowed CSS injection (@import,url()exfiltration) and swallowed the following page content. Upgrade recommended. - add OSS Scanner configuration (
.oss-scanner/, excluded from Composer dist via export-ignore) and document how to run the tests