CycleWire v1.0.1
Security
htmlrefusedjavascript:URLs only in the simplest case. A value split across
interpolations (href="${a}${b}"), passed as an array or as nestedhtml, preceded by
fixed text such as a space, or set through SVG animation attributes (to,from,by,
values) could still produce a script URL. The whole attribute value is now checked as
the browser reads it, and templates that end inside a tag, a comment or a raw-text
element are refused.data-cw-ignoreonly stopped event handling from reaching outer bindings. Elements
inside it that carried their own bindings still ran, andload/visibletriggers,
preloads and signals bindings inside it still activated. Nothing inside it activates
now, across shadow roots too.- Signals
attr.*bindings could write event handlers,srcdocand script URLs.
They are refused now, with a warning in the development build.
Changed
- Size budgets:
dom.min.js2304 B andsignals.min.js3200 B (brotli), for the checks
above.
Install
npm install cyclewire@1.0.1<script src="https://cdn.jsdelivr.net/npm/cyclewire@1.0.1/dist/cyclewire.global.min.js"
integrity="sha384-gc0AJD/HiRsZkqVJzFpkiXC9MICQD/4TJxO0Ym9KXeCsg542FsOPkcm6nsvtg0SQ"
crossorigin="anonymous" defer></script>Subresource Integrity
| File | SRI |
|---|---|
cyclewire.global.min.js |
sha384-gc0AJD/HiRsZkqVJzFpkiXC9MICQD/4TJxO0Ym9KXeCsg542FsOPkcm6nsvtg0SQ |
cyclewire.full.global.min.js |
sha384-k7XXWn8CMXKeBQZj6Bdc+rPV9OXKnchHO9qn47T20/Tdj3RCAA/prZrkTAOAAgZe |
cyclewire.min.js |
sha384-h5cx8AujO5AU+RULhp/Qm8yWXUPGqIzuK4IcR87QL3AnJLAmzclEVHMEwsu6pPJH |
bootstrap.min.js |
sha384-R+KFPGlTWajb/qSGqKkk6tWj/EJMbeFxYd4V0IVP4Y5muFNoAs4gcbUNKY3PMIkM |
css.min.js |
sha384-afUiywAjluRvzALKwWR4wZ8t0cTGdZk5Nh3Uk0wpSCGpF077wOXq6MGVI56NZ2hJ |
dom.min.js |
sha384-jvuCmVxMVZr05rTvPMMkQ55xoN4xgM1pzFsCH6nwcBwVyUJhzzZUbL2DSqEfSNFP |
morph.min.js |
sha384-YfcB2wsEm9aMmyeKNU+BGCB7OAoiqmGPzY/habddugYDF/CKj1gXBwfyY+BleIs7 |
signals.min.js |
sha384-O2d0eo4HLwzgeothtcouNS8WRFneFuTbUtglREEnQlXrnb6r+CBMFbBpLwFPf/Zt |
Full changelog: CHANGELOG.md