sanitize-html
Advanced tools
Comparing version 1.20.0 to 1.20.1
## Changelog | ||
1.20.1: Fix failing tests, add CircleCI config | ||
1.20.0: reduced size of npm package via the `files` key; we only need to publish what's in `dist`. Thanks to Steven. There should be zero impact on behavior, minor version bump is precautionary. | ||
@@ -179,2 +181,1 @@ | ||
0.1.0: initial release. | ||
@@ -550,5 +550,5 @@ 'use strict'; | ||
return filteredAST.nodes[0].nodes.reduce(function (extractedAttributes, attributeObject) { | ||
extractedAttributes.push(attributeObject.prop + ':' + attributeObject.value + ';'); | ||
extractedAttributes.push(attributeObject.prop + ':' + attributeObject.value); | ||
return extractedAttributes; | ||
}, []).join(''); | ||
}, []).join(';'); | ||
} | ||
@@ -555,0 +555,0 @@ |
{ | ||
"name": "sanitize-html", | ||
"version": "1.20.0", | ||
"version": "1.20.1", | ||
"description": "Clean up user-submitted HTML, preserving whitelisted elements and whitelisted attributes on a per-element basis", | ||
@@ -5,0 +5,0 @@ "main": "dist/index.js", |
# sanitize-html | ||
<a href="http://apostrophenow.org/"><img src="https://raw.github.com/punkave/sanitize-html/master/logos/logo-box-madefor.png" align="right" /></a> | ||
[![CircleCI](https://circleci.com/gh/punkave/sanitize-html/tree/master.svg?style=svg)](https://circleci.com/gh/punkave/sanitize-html/tree/master) | ||
<a href="https://apostrophecms.org/"><img src="https://raw.github.com/punkave/sanitize-html/master/logos/logo-box-madefor.png" align="right" /></a> | ||
`sanitize-html` provides a simple HTML sanitizer with a clear API. | ||
@@ -6,0 +8,0 @@ |
Sorry, the diff of this file is too big to display
Sorry, the diff of this file is too big to display
License Policy Violation
LicenseThis package is not allowed per your license policy. Review the package's license to ensure compliance.
Found 1 instance in 1 package
New author
Supply chain riskA new npm collaborator published a version of the package for the first time. New collaborators are usually benign additions to a project, but do indicate a change to the security surface area of a package.
Found 1 instance in 1 package
Environment variable access
Supply chain riskPackage accesses environment variables, which may be a sign of credential stuffing or data theft.
Found 1 instance in 1 package
License Policy Violation
LicenseThis package is not allowed per your license policy. Review the package's license to ensure compliance.
Found 1 instance in 1 package
Filesystem access
Supply chain riskAccesses the file system, and could potentially read sensitive data.
Found 1 instance in 1 package
504
1048905
21077
20
21