DarkRoomLibrary v1.2.5
This security patch updates the HTML sanitizer dependency without changing product behavior.
Changes
- Updated
org.jsoup:jsoupfrom1.22.2to1.23.1. - Resolved
GHSA-pmhh-3w7g-xqp8, which affects Cleaner configurations that permit custom raw-text elements. - Made no business logic, database schema, API, or frontend changes.
Verification boundary
- Dependabot PR #9 passed the complete CI and Security workflows before merge.
- The merge commit passed CI, Security, and GitHub Pages, and GitHub marked the alert as fixed.
- The release workflow reruns complete CI on the tag commit and requires a successful Security workflow for the same commit.
- Existing single-instance, browser, concurrency, middleware-degradation, and historical three-instance evidence remains explicitly dated; this dependency-only patch does not claim to have rerun those real chains.