Release SVG Tools 0.2.0
Verify / verify (push) Canceled after 0s

This commit is contained in:
2026-09-02 04:48:12 +02:00
parent 902ff61e8d
commit 0c7736dbc3
18 changed files with 366 additions and 70 deletions
+4
View File
@@ -73,6 +73,10 @@ and DOMPurify remain dependency/security boundaries. Bounded data URLs may still
decode expensive images within the raster-pixel limits. CSP header regressions
can break the fixed controller even when the content remains inert.
DOMPurify is pinned in the lockfile and its SVG policy is covered by the
project-authored adversarial suite. Dependency updates must run both
`npm run test:security` and the browser tests before release.
Report vulnerabilities privately through the repository owner/contact before
opening a public issue when disclosure could expose users. Include the SVG,
browser, deployment headers and observed network/execution behavior without