Skip to content

Build(deps): bump com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer from 20260313.1 to 20260922.1 - #3299

Open
dependabot[bot] wants to merge 2 commits into
masterfrom
dependabot/gradle/com.googlecode.owasp-java-html-sanitizer-owasp-java-html-sanitizer-20260922.1
Open

dependabot[bot] wants to merge 2 commits into
masterfrom
dependabot/gradle/com.googlecode.owasp-java-html-sanitizer-owasp-java-html-sanitizer-20260922.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 27, 2026

Copy link
Copy Markdown
Contributor

Bumps com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer from 20260313.1 to 20260922.1.

Release notes

Sourced from com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer's releases.

Release 20260922.1

Changelog

  • c2042c0 Release version 20260922.1 (GitHub Actions)
  • ea86ffa Encode CSS URL content after rewriting (Jim Manico)
  • de7555c Record GHSA-vqwm-jvq2-mfwc and pin its reported cases (Jim Manico)
  • 0261fc6 Prepare for next development version (GitHub Actions)

Contributors

We'd like to thank the following people for their contributions:

  • Jim Manico

Release 20260921.1

Changelog

  • b8d90c9 Release version 20260921.1 (GitHub Actions)
  • 37d9212 Preserve form text policy across implied tables (Jim Manico)
  • 7ae2b5c Stabilize list-item closure across output contexts (Jim Manico)
  • 9059be1 Preserve text after an ignored form in a dropped table (Jim Manico)
  • 27d2c04 Preserve nested list context for browser tree stability (Jim Manico)
  • 1901496 Cover dropped-template list residuals (Jim Manico)
  • 0a55504 Stabilize list contexts after dropped wrappers (Jim Manico)
  • 6e0254c Stabilize text after bare dropped-table parts (Jim Manico)
  • 7b4e234 Take the review: keep select retirement synchronized and scoped (Jim Manico)
  • 50a7d01 Fix browser-round-trip text gates for #497 (Jim Manico)
  • 9ebd255 Take the review: keep the rule to the container, not to table scope (Jim Manico)
  • 6469377 Take the third review: keep the formatting a browser keeps, and say what changed (Jim Manico)
  • ee953d2 Take the second review: judge every barrier by the output, keep the option's item (Jim Manico)
  • afe8e8e Take the review: bound the resumption queue, judge barriers by the output (Jim Manico)
  • 2a9ede4 Take the probe: do not resume formatting inside an element read as raw text (Jim Manico)
  • a9f9abb Close the open list item for a list item start tag, through formatting (Jim Manico)
  • f9a0c87 Take the review: a dropped template bounds no table scope, and holds a col directly too (Jim Manico)
  • 24c6c78 Give a caption or column group under a dropped template its table in Sanitizers.TABLES (Jim Manico)
  • 8b6c865 Take the second review: push the table out from below the dropped entries (Jim Manico)
  • 2560fc8 Take the probe: stop the select's scan at the select's own logical item (Jim Manico)
  • 1cb96ab Take the review: judge the select's place by the nearest emitted ancestor, keep the dropped cell's end tag (Jim Manico)
  • ec40ba1 Take the third review: the output decides an element's containment under a known root (Jim Manico)
  • 2c5a5c6 Keep item 2 out: judge only an option under a dropped template here (Jim Manico)
  • 3120ddc Take the probe: an option under a dropped template inside a table gets a foster-parented select (Jim Manico)
  • 61c3ffe Take the probe: forward foreign table parts only while the input names a root, outside raw-text nodes (Jim Manico)
  • d8c9c25 Take the review: judge a dropped template's parts in the output, foster-parent the select out of a kept table (Jim Manico)
  • 3d02eb5 Take the second review: forward foreign table parts, no select for a foreign option (Jim Manico)
  • 16e9003 Take the probe: keep the table parts' wrappers as they were, judge parts under a dropped template where it stood (Jim Manico)
  • 780c355 Apply the free wrappers under every container past the wrapper's set (Jim Manico)
  • e07877a Take the probe: keep HTML containment for a raw-text-named foreign node (Jim Manico)
  • b75252a Take the review: bound the root by what the parsers still have open (Jim Manico)
  • 4aff8a1 Take the review: leave more of a document behind before the throw (Jim Manico)
  • 9a1979e Judge content below the foreign root as in a fresh body (Jim Manico)
  • 74d8e25 Test that openDocument resets what a throwing receiver left open (Jim Manico)

... (truncated)

Commits
  • c2042c0 Release version 20260922.1
  • 2c67d53 Merge commit from fork
  • ea86ffa Encode CSS URL content after rewriting
  • 2045690 Merge pull request #505 from OWASP/ghsa-vqwm-docs-and-tests
  • de7555c Record GHSA-vqwm-jvq2-mfwc and pin its reported cases
  • 0261fc6 Prepare for next development version
  • b8d90c9 Release version 20260921.1
  • 7240c23 Merge pull request #504 from OWASP/fix/492-3-form-text-context
  • 37d9212 Preserve form text policy across implied tables
  • be813dd Merge pull request #500 from OWASP/list-item-after-resumed-formatting-492-8
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

…-html-sanitizer

Bumps [com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer](https://github.com/OWASP/java-html-sanitizer) from 20260313.1 to 20260922.1.
- [Release notes](https://github.com/OWASP/java-html-sanitizer/releases)
- [Commits](OWASP/java-html-sanitizer@release-20260313.1...release-20260922.1)

---
updated-dependencies:
- dependency-name: com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer
  dependency-version: '20260922.1'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Sep 27, 2026
@FlowCryptRobot
FlowCryptRobot enabled auto-merge (squash) September 27, 2026 20:04
…a-html-sanitizer-owasp-java-html-sanitizer-20260922.1
@dependabot @github

dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown
Contributor Author

A newer version of com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer exists, but since this PR has been edited by someone other than Dependabot I haven't updated it. You'll get a PR for the updated version as normal once this PR is merged.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants