@@ -73,6 +73,10 @@ and DOMPurify remain dependency/security boundaries. Bounded data URLs may still
|
||||
decode expensive images within the raster-pixel limits. CSP header regressions
|
||||
can break the fixed controller even when the content remains inert.
|
||||
|
||||
DOMPurify is pinned in the lockfile and its SVG policy is covered by the
|
||||
project-authored adversarial suite. Dependency updates must run both
|
||||
`npm run test:security` and the browser tests before release.
|
||||
|
||||
Report vulnerabilities privately through the repository owner/contact before
|
||||
opening a public issue when disclosure could expose users. Include the SVG,
|
||||
browser, deployment headers and observed network/execution behavior without
|
||||
|
||||
Reference in New Issue
Block a user