v1.1.24
Security
- CSP
img-srctightened to'self' data:— removed thehttps:scheme wildcard; the site loads no external images (verified by repo-wide scan), so arbitrary-origin image loads are no longer permitted. rel="noopener noreferrer"on external outbound links — GitHub links inCompareCTA, Footer outbound links, and repo/license links on/changelog/and/license/now carry both hints; defense-in-depth (notarget="_blank"exists site-wide) plus Referer-leak prevention.
Full details in CHANGELOG.md.