mganss / HtmlSanitizer

Cleans HTML to avoid XSS attacks
MIT License
1.55k stars 200 forks source link

Bump AngleSharp from 0.17.1 to 1.0.1 #424

Closed dependabot[bot] closed 1 year ago

dependabot[bot] commented 1 year ago

Bumps AngleSharp from 0.17.1 to 1.0.1.

Release notes

Sourced from AngleSharp's releases.

1.0.1

Released on Monday, January 16 2023

What's Changed

  • Fixed entities in noscript being double encoded (#1070)
  • Added previous Event constructor overload for ABI compatibility
  • Added README to NuGet package

Full Changelog: https://github.com/AngleSharp/AngleSharp/compare/v1.0.0...v1.0.1

1.0.0

Released on Tuesday, January 10 2023

What's Changed

New Contributors

Full Changelog: https://github.com/AngleSharp/AngleSharp/compare/v0.17.1...v1.0.0

1.0.0-alpha-231

Released on Tuesday, January 10 2023

  • Updated build system to use NUKE instead of CAKE (#1075) @​driekus77
  • Fixed TagClosedWrong error with nested formatting elements (#1052)
  • Fixed performance issue within deeply nested structures (#1066) @​heinrich-ulbricht
  • Fixed decoding of entities in noscript elements without scripting (#1070)
  • Fixed setting templte content using InnerHtml (#1072)
  • Fixed TreeWalker throwing NullReferenceException (#1073)
  • Improved GetItemByIndex performance (#1050) @​egil
  • Improved nullability (#1057) @​jodydonetti
  • Improved CSS selectors by counting the specificity properly (#1080) @​patrikwlund
  • Added GetComposedPath and IsComposed to the Event class (#1053)

... (truncated)

Commits


Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
> **Note** > Automatic rebases have been disabled on this pull request as it has been open for over 30 days.
codecov[bot] commented 1 year ago

Codecov Report

Base: 94.66% // Head: 94.66% // No change to project coverage :thumbsup:

Coverage data is based on head (84ec7ef) compared to base (eea75f5). Patch has no changes to coverable lines.

Additional details and impacted files ```diff @@ Coverage Diff @@ ## master #424 +/- ## ======================================= Coverage 94.66% 94.66% ======================================= Files 6 6 Lines 843 843 Branches 83 83 ======================================= Hits 798 798 Misses 34 34 Partials 11 11 ``` Help us with your feedback. Take ten seconds to tell us [how you rate us](https://about.codecov.io/nps?utm_medium=referral&utm_source=github&utm_content=comment&utm_campaign=pr+comments&utm_term=Michael+Ganss). Have a feature suggestion? [Share it here.](https://app.codecov.io/gh/feedback/?utm_medium=referral&utm_source=github&utm_content=comment&utm_campaign=pr+comments&utm_term=Michael+Ganss)

:umbrella: View full report at Codecov.
:loudspeaker: Do you have feedback about the report comment? Let us know in this issue.

Tealons commented 1 year ago

Can you merge this one and release a new version? We have a direct dependency on AngleSharp and we cannot upgrade because HtmlSanitizer has not upgraded yet.

mganss commented 1 year ago

@Tealons HtmlSanitizer also depends on AngleSharp.Css. The latest version of AngleSharp.Css is not yet compatible with AngleSharp 1.0.1, see https://github.com/AngleSharp/AngleSharp.Css/issues/130

Tealons commented 1 year ago

Ah, I missed that. Thanks for explaining it!

ghost commented 1 year ago

@Tealons HtmlSanitizer also depends on AngleSharp.Css. The latest version of AngleSharp.Css is not yet compatible with AngleSharp 1.0.1, see AngleSharp/AngleSharp.Css#130

@mganss It is already solved.

stoicz commented 1 year ago

@Tealons HtmlSanitizer also depends on AngleSharp.Css. The latest version of AngleSharp.Css is not yet compatible with AngleSharp 1.0.1, see AngleSharp/AngleSharp.Css#130

@mganss It is already solved.

@hardhub Haven't they just closed that issue, because it's on their radar as part of the v1.0 milestone?

image
ghost commented 1 year ago

@stoicz I see, it is not released yet. False start :)

dependabot[bot] commented 1 year ago

Superseded by #448.