Skip to content

v0.1.2

Pre-release
Pre-release

Choose a tag to compare

@TimG1804 TimG1804 released this 20 Aug 13:16
· 15 commits to main since this release

Security

Fixes a DOM XSS in the dropdown trigger label (#1). option.text returns decoded text, so markup that the page had correctly escaped was turned back into live HTML and executed. Anyone whose option labels carry user-supplied data should update from 0.1.1.

What's Changed

● fix: regenerate package-lock.json
● fix: build the trigger label with textContent instead of innerHTML
● fix: escape option values used in querySelector
● fix: ignore empty tokens in assignClasses

Notes added after the fact — the release run for this tag failed before it could create them.