Skip to content

Conversation

@stklcode
Copy link
Owner

@stklcode stklcode commented Feb 4, 2025

Backport security-related bugfix from develop branch (#28), update dev-environment and bump plugin version.

Ticker ID is user input and may contain literally anything. While this
is properly escaped in the internal query, we should also escape it in
the generated HTML output.
@stklcode stklcode added this to the 1.2.3 milestone Feb 4, 2025
@stklcode stklcode self-assigned this Feb 4, 2025
@stklcode stklcode changed the base branch from develop to stable February 4, 2025 17:21
@stklcode stklcode merged commit 8094623 into stable Feb 4, 2025
18 checks passed
@sonarqubecloud
Copy link

sonarqubecloud bot commented Feb 4, 2025

@stklcode stklcode deleted the release/1.2.3 branch February 4, 2025 17:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants