7.1.0 (2026-09-28)
Fixed Bugs
-
rerender when the HTML sanitizer changes (commit 99840af)
-
preserve inline tokens in checkbox labels (commit a1a9076)
- Wrap existing inline tokens with structured labels to preserve
- formatting and HTML escaping.
-
preserve safe defaults in custom configuration (commit dcb2788)
- Merge custom options over rendering defaults while keeping trust
- disabled unless explicitly overridden.
-
isolate rendering state and enforce safe defaults (commit 4905824)
- Keep strict defaults, serialize library initialization and rendering,
- and cache sanitized SVGs per preview and code block.
- Reject outdated async results after content or policy changes and
- rebind interactions when cached SVGs create new DOM.
-
sanitize chart options before rendering (commit 22307aa)
- Use rich-text tooltips, escape inherited DataView labels and restrict
- links across base, timeline and media options. Keep parsing and
- sanitization independently configurable.
- Restore source text after render failures and recognize closed
- backtick, tilde and nested fences.
Others
- docs(skills): document renderer security configuration (commit 55916b4)
- Describe independent ECharts parsing and rendering policies, trusted
- renderer opt-ins and Mermaid cache invalidation.
Full Changelog: v7.0.0...v7.1.0