Skip to content

Escape entry language and CDATA terminators; release 0.18.0 - #431

Merged
benbalter merged 2 commits into
masterfrom
escape-entry-lang
Sep 29, 2026
Merged

benbalter merged 2 commits into
masterfrom
escape-entry-lang

Conversation

@benbalter

Copy link
Copy Markdown
Contributor

Security fix, with regression tests. The advisory will be published once this is released.

🤖 Generated with Claude Code

benbalter and others added 2 commits September 29, 2026 18:20
XML-escape post.lang and site.lang in the feed's xml:lang and hreflang
attributes, and split any "]]>" in post content and summaries so it
cannot terminate the surrounding CDATA section.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@benbalter
benbalter merged commit 61a0447 into master Sep 29, 2026
6 checks passed
@benbalter
benbalter deleted the escape-entry-lang branch September 29, 2026 23:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant