[Ruby] Release 0.22.0
·
3 commits
to master
since this release
Changed
- Update
cssparserto0.38. - Update
html5everto0.40. - Update
selectorsto0.41. - Update
magnusto0.9.
Fixed
remove_inlined_selectorsremoved@-rules from the<style>blocks it rewrites (it should remove only inlined selectors).
Security
classattribute values not HTML-escaped in the output, allowing markup injection via"in a class value. GHSA-jh54-c7gc-mvcc