Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security comment for unsafe #245

Merged
merged 1 commit into from
Jan 9, 2024
Merged

Security comment for unsafe #245

merged 1 commit into from
Jan 9, 2024

Conversation

vonox7
Copy link
Contributor

@vonox7 vonox7 commented Oct 30, 2023

There is no explanation for why "unsafe" is considered "not safe." A developer who is unaware of the implications might not realize that this is related to XSS and currently has no straightforward way of figuring this out.

This comment provides:

  • An explanation of what is happening.
  • The use of technical terms (XSS) to allow users to search for more relevant information.
  • Two action items.

There is no explanation for why "unsafe" is considered "not safe." A developer who is unaware of the implications might not realize that this is related to XSS and currently has no straightforward way of figuring this out.

This comment provides:
* An explanation of what is happening.
* The use of technical terms (XSS) to allow users to search for more relevant information.
* Two action items.
@e5l e5l self-assigned this Jan 9, 2024
@e5l e5l self-requested a review January 9, 2024 07:54
@e5l
Copy link
Member

e5l commented Jan 9, 2024

Hey @vonox7, thanks for the PR. That's a good note, LGTM

@e5l e5l merged commit 05b8971 into Kotlin:master Jan 9, 2024
DonRobo referenced this pull request in DonRobo/home-former Jul 25, 2024
)

[![Mend
Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com)

This PR contains the following updates:

| Package | Change | Age | Adoption | Passing | Confidence |
|---|---|---|---|---|---|
|
[org.jetbrains.kotlinx:kotlinx-html-jvm](https://togithub.com/Kotlin/kotlinx.html)
| `0.10.1` -> `0.11.0` |
[![age](https://developer.mend.io/api/mc/badges/age/maven/org.jetbrains.kotlinx:kotlinx-html-jvm/0.11.0?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|
[![adoption](https://developer.mend.io/api/mc/badges/adoption/maven/org.jetbrains.kotlinx:kotlinx-html-jvm/0.11.0?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|
[![passing](https://developer.mend.io/api/mc/badges/compatibility/maven/org.jetbrains.kotlinx:kotlinx-html-jvm/0.10.1/0.11.0?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|
[![confidence](https://developer.mend.io/api/mc/badges/confidence/maven/org.jetbrains.kotlinx:kotlinx-html-jvm/0.10.1/0.11.0?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>Kotlin/kotlinx.html
(org.jetbrains.kotlinx:kotlinx-html-jvm)</summary>

###
[`v0.11.0`](https://togithub.com/Kotlin/kotlinx.html/releases/tag/0.11.0)

[Compare
Source](https://togithub.com/Kotlin/kotlinx.html/compare/0.10.1...0.11.0)

#### What's Changed

- Add the `crossorigin` attribute to the `<script>` element by
[@&#8203;lorenzsimon](https://togithub.com/lorenzsimon) in
[https://github.com/Kotlin/kotlinx.html/pull/248](https://togithub.com/Kotlin/kotlinx.html/pull/248)
- Security comment for unsafe by
[@&#8203;vonox7](https://togithub.com/vonox7) in
[https://github.com/Kotlin/kotlinx.html/pull/245](https://togithub.com/Kotlin/kotlinx.html/pull/245)
- add <u></u> tag by [@&#8203;EnvyIT](https://togithub.com/EnvyIT) in
[https://github.com/Kotlin/kotlinx.html/pull/241](https://togithub.com/Kotlin/kotlinx.html/pull/241)
- Converted Repository into a class to force its instantiation in each
execution of the generate task by
[@&#8203;severn-everett](https://togithub.com/severn-everett) in
[https://github.com/Kotlin/kotlinx.html/pull/222](https://togithub.com/Kotlin/kotlinx.html/pull/222)
- Fix description of samp and add strike tag by
[@&#8203;MarcinAman](https://togithub.com/MarcinAman) in
[https://github.com/Kotlin/kotlinx.html/pull/184](https://togithub.com/Kotlin/kotlinx.html/pull/184)
- Update Kotlin version in `README.md` badge by
[@&#8203;SimonMarquis](https://togithub.com/SimonMarquis) in
[https://github.com/Kotlin/kotlinx.html/pull/252](https://togithub.com/Kotlin/kotlinx.html/pull/252)
- Add wasmJs target support. by
[@&#8203;IlyaGulya](https://togithub.com/IlyaGulya) in
[https://github.com/Kotlin/kotlinx.html/pull/251](https://togithub.com/Kotlin/kotlinx.html/pull/251)
- Added loading attribute to img tag by
[@&#8203;severn-everett](https://togithub.com/severn-everett) in
[https://github.com/Kotlin/kotlinx.html/pull/220](https://togithub.com/Kotlin/kotlinx.html/pull/220)
- Provides a short access to document elements by ID via delegated by
[@&#8203;jonnyzzz](https://togithub.com/jonnyzzz) in
[https://github.com/Kotlin/kotlinx.html/pull/126](https://togithub.com/Kotlin/kotlinx.html/pull/126)
- Adding full list of HTML entities by
[@&#8203;severn-everett](https://togithub.com/severn-everett) in
[https://github.com/Kotlin/kotlinx.html/pull/209](https://togithub.com/Kotlin/kotlinx.html/pull/209)
- fix samp documentation by
[@&#8203;KotlinIsland](https://togithub.com/KotlinIsland) in
[https://github.com/Kotlin/kotlinx.html/pull/172](https://togithub.com/Kotlin/kotlinx.html/pull/172)
- Added onmouseenter and onmouseleave attributes by
[@&#8203;vitek999](https://togithub.com/vitek999) in
[https://github.com/Kotlin/kotlinx.html/pull/169](https://togithub.com/Kotlin/kotlinx.html/pull/169)

#### New Contributors

- [@&#8203;lorenzsimon](https://togithub.com/lorenzsimon) made their
first contribution in
[https://github.com/Kotlin/kotlinx.html/pull/248](https://togithub.com/Kotlin/kotlinx.html/pull/248)
- [@&#8203;vonox7](https://togithub.com/vonox7) made their first
contribution in
[https://github.com/Kotlin/kotlinx.html/pull/245](https://togithub.com/Kotlin/kotlinx.html/pull/245)
- [@&#8203;EnvyIT](https://togithub.com/EnvyIT) made their first
contribution in
[https://github.com/Kotlin/kotlinx.html/pull/241](https://togithub.com/Kotlin/kotlinx.html/pull/241)
- [@&#8203;MarcinAman](https://togithub.com/MarcinAman) made their first
contribution in
[https://github.com/Kotlin/kotlinx.html/pull/184](https://togithub.com/Kotlin/kotlinx.html/pull/184)
- [@&#8203;SimonMarquis](https://togithub.com/SimonMarquis) made their
first contribution in
[https://github.com/Kotlin/kotlinx.html/pull/252](https://togithub.com/Kotlin/kotlinx.html/pull/252)
- [@&#8203;IlyaGulya](https://togithub.com/IlyaGulya) made their first
contribution in
[https://github.com/Kotlin/kotlinx.html/pull/251](https://togithub.com/Kotlin/kotlinx.html/pull/251)
- [@&#8203;jonnyzzz](https://togithub.com/jonnyzzz) made their first
contribution in
[https://github.com/Kotlin/kotlinx.html/pull/126](https://togithub.com/Kotlin/kotlinx.html/pull/126)
- [@&#8203;KotlinIsland](https://togithub.com/KotlinIsland) made their
first contribution in
[https://github.com/Kotlin/kotlinx.html/pull/172](https://togithub.com/Kotlin/kotlinx.html/pull/172)
- [@&#8203;vitek999](https://togithub.com/vitek999) made their first
contribution in
[https://github.com/Kotlin/kotlinx.html/pull/169](https://togithub.com/Kotlin/kotlinx.html/pull/169)

**Full Changelog**:
Kotlin/kotlinx.html@0.10.1...0.11.0

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend
Renovate](https://www.mend.io/free-developer-tools/renovate/). View the
[repository job
log](https://developer.mend.io/github/DonRobo/home-former).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy40MzguMCIsInVwZGF0ZWRJblZlciI6IjM3LjQzOC4wIiwidGFyZ2V0QnJhbmNoIjoiZGV2ZWxvcCIsImxhYmVscyI6W119-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants