v0.1.2
Pre-release
Pre-release
Security
Fixes a DOM XSS in the dropdown trigger label (#1). option.text returns decoded text, so markup that the page had correctly escaped was turned back into live HTML and executed. Anyone whose option labels carry user-supplied data should update from 0.1.1.
What's Changed
● fix: regenerate package-lock.json
● fix: build the trigger label with textContent instead of innerHTML
● fix: escape option values used in querySelector
● fix: ignore empty tokens in assignClasses
Notes added after the fact — the release run for this tag failed before it could create them.