Skip to content

Bump com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer from 20260313.1 to 20260922.1 - #1561

Merged
solomax merged 1 commit into
masterfrom
dependabot/maven/com.googlecode.owasp-java-html-sanitizer-owasp-java-html-sanitizer-20260922.1
Sep 28, 2026
Merged

solomax merged 1 commit into
masterfrom
dependabot/maven/com.googlecode.owasp-java-html-sanitizer-owasp-java-html-sanitizer-20260922.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 27, 2026

Copy link
Copy Markdown
Contributor

Bumps com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer from 20260313.1 to 20260922.1.

Release notes

Sourced from com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer's releases.

Release 20260922.1

Changelog

  • c2042c0 Release version 20260922.1 (GitHub Actions)
  • ea86ffa Encode CSS URL content after rewriting (Jim Manico)
  • de7555c Record GHSA-vqwm-jvq2-mfwc and pin its reported cases (Jim Manico)
  • 0261fc6 Prepare for next development version (GitHub Actions)

Contributors

We'd like to thank the following people for their contributions:

  • Jim Manico

Release 20260921.1

Changelog

  • b8d90c9 Release version 20260921.1 (GitHub Actions)
  • 37d9212 Preserve form text policy across implied tables (Jim Manico)
  • 7ae2b5c Stabilize list-item closure across output contexts (Jim Manico)
  • 9059be1 Preserve text after an ignored form in a dropped table (Jim Manico)
  • 27d2c04 Preserve nested list context for browser tree stability (Jim Manico)
  • 1901496 Cover dropped-template list residuals (Jim Manico)
  • 0a55504 Stabilize list contexts after dropped wrappers (Jim Manico)
  • 6e0254c Stabilize text after bare dropped-table parts (Jim Manico)
  • 7b4e234 Take the review: keep select retirement synchronized and scoped (Jim Manico)
  • 50a7d01 Fix browser-round-trip text gates for #497 (Jim Manico)
  • 9ebd255 Take the review: keep the rule to the container, not to table scope (Jim Manico)
  • 6469377 Take the third review: keep the formatting a browser keeps, and say what changed (Jim Manico)
  • ee953d2 Take the second review: judge every barrier by the output, keep the option's item (Jim Manico)
  • afe8e8e Take the review: bound the resumption queue, judge barriers by the output (Jim Manico)
  • 2a9ede4 Take the probe: do not resume formatting inside an element read as raw text (Jim Manico)
  • a9f9abb Close the open list item for a list item start tag, through formatting (Jim Manico)
  • f9a0c87 Take the review: a dropped template bounds no table scope, and holds a col directly too (Jim Manico)
  • 24c6c78 Give a caption or column group under a dropped template its table in Sanitizers.TABLES (Jim Manico)
  • 8b6c865 Take the second review: push the table out from below the dropped entries (Jim Manico)
  • 2560fc8 Take the probe: stop the select's scan at the select's own logical item (Jim Manico)
  • 1cb96ab Take the review: judge the select's place by the nearest emitted ancestor, keep the dropped cell's end tag (Jim Manico)
  • ec40ba1 Take the third review: the output decides an element's containment under a known root (Jim Manico)
  • 2c5a5c6 Keep item 2 out: judge only an option under a dropped template here (Jim Manico)
  • 3120ddc Take the probe: an option under a dropped template inside a table gets a foster-parented select (Jim Manico)
  • 61c3ffe Take the probe: forward foreign table parts only while the input names a root, outside raw-text nodes (Jim Manico)
  • d8c9c25 Take the review: judge a dropped template's parts in the output, foster-parent the select out of a kept table (Jim Manico)
  • 3d02eb5 Take the second review: forward foreign table parts, no select for a foreign option (Jim Manico)
  • 16e9003 Take the probe: keep the table parts' wrappers as they were, judge parts under a dropped template where it stood (Jim Manico)
  • 780c355 Apply the free wrappers under every container past the wrapper's set (Jim Manico)
  • e07877a Take the probe: keep HTML containment for a raw-text-named foreign node (Jim Manico)
  • b75252a Take the review: bound the root by what the parsers still have open (Jim Manico)
  • 4aff8a1 Take the review: leave more of a document behind before the throw (Jim Manico)
  • 9a1979e Judge content below the foreign root as in a fresh body (Jim Manico)
  • 74d8e25 Test that openDocument resets what a throwing receiver left open (Jim Manico)

... (truncated)

Commits
  • c2042c0 Release version 20260922.1
  • 2c67d53 Merge commit from fork
  • ea86ffa Encode CSS URL content after rewriting
  • 2045690 Merge pull request #505 from OWASP/ghsa-vqwm-docs-and-tests
  • de7555c Record GHSA-vqwm-jvq2-mfwc and pin its reported cases
  • 0261fc6 Prepare for next development version
  • b8d90c9 Release version 20260921.1
  • 7240c23 Merge pull request #504 from OWASP/fix/492-3-form-text-context
  • 37d9212 Preserve form text policy across implied tables
  • be813dd Merge pull request #500 from OWASP/list-item-after-resumed-formatting-492-8
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer](https://github.com/OWASP/java-html-sanitizer) from 20260313.1 to 20260922.1.
- [Release notes](https://github.com/OWASP/java-html-sanitizer/releases)
- [Commits](OWASP/java-html-sanitizer@release-20260313.1...release-20260922.1)

---
updated-dependencies:
- dependency-name: com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer
  dependency-version: '20260922.1'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Sep 27, 2026
@dependabot
dependabot Bot deployed to CI_DEPLOY September 27, 2026 22:53 Active
@solomax
solomax merged commit 9ff2333 into master Sep 28, 2026
1 check passed
@dependabot
dependabot Bot deleted the dependabot/maven/com.googlecode.owasp-java-html-sanitizer-owasp-java-html-sanitizer-20260922.1 branch September 28, 2026 03:29

This branch was successfully deployed

1 active deployment
CI_DEPLOY — 131f2e8e Deployed Sep 27, 2026 by dependabot[bot] via Java 17 Test #1738
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant