Releases: 3m5/squirrel-select
Release list
v0.1.5
What's Changed
● chore: update dev dependencies by @TimG1804● ci: harden release workflow by @TimG1804
● ci: add dependabot for npm and github-actions by @TimG1804
● update release as NPM package to support OIDC / Trusted Publisher workflow by @robert-heinig
● add repository.url to package.json by @robert-heinig
● ci: restore workflow hardening and tolerate an existing release by @TimG1804
● fix: correct repository url format in package.json by @TimG1804
● chore: release 0.1.5 by @TimG1804
v0.1.2
Security
Fixes a DOM XSS in the dropdown trigger label (#1). option.text returns decoded text, so markup that the page had correctly escaped was turned back into live HTML and executed. Anyone whose option labels carry user-supplied data should update from 0.1.1.
What's Changed
● fix: regenerate package-lock.json
● fix: build the trigger label with textContent instead of innerHTML
● fix: escape option values used in querySelector
● fix: ignore empty tokens in assignClasses
Notes added after the fact — the release run for this tag failed before it could create them.
v0.1.1
What's Changed
● docs: remove empty line at the end of README by @TimG1804● Merge remote-tracking branch 'origin/main' by @TimG1804
● docs: minor revision by @robert-heinig