From 3556e2b44f7401aaccbb10e2abac4e044391267a Mon Sep 17 00:00:00 2001 From: Mike Dalessio Date: Sun, 28 Oct 2018 15:11:46 -0400 Subject: [PATCH] add formatting to CHANGELOG [skip ci] --- CHANGELOG.md | 66 +++++++++++++++++++++++++++------------------------- 1 file changed, 34 insertions(+), 32 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index ddcacdec..28135a08 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -20,6 +20,8 @@ attribute scrubbers should they need to address CVE-2018-8048. ## 2.2.1 / 2018-03-19 +### Security + Addresses CVE-2018-8048. Loofah allowed non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments. This CVE's public notice is at https://github.com/flavorjones/loofah/issues/144 @@ -27,7 +29,7 @@ This CVE's public notice is at https://github.com/flavorjones/loofah/issues/144 ## 2.2.0 / 2018-02-11 -Features: +### Features: * Support HTML5 `
` tag. #133 (Thanks, @MothOnMars!) * Recognize HTML5 block elements. #136 (Thanks, @MothOnMars!) @@ -35,32 +37,32 @@ Features: * Support for whitelisting CSS functions, initially just `calc` and `rgb`. #122/#123/#129 (Thanks, @NikoRoberts!) * Whitelist CSS property `list-style-type`. #68/#137/#142 (Thanks, @andela-ysanni and @NikoRoberts!) -Bugfixes: +### Bugfixes: * Properly handle nested `script` tags. #127. ## 2.1.1 / 2017-09-24 -Bugfixes: +### Bugfixes: * Removed warning for unused variable. #124 (Thanks, @y-yagi!) ## 2.1.0 / 2017-09-24 -Notes: +### Notes: * Re-implemented CSS parsing and sanitization using the [crass](https://github.com/rgrove/crass) library. #91 -Features: +### Features: * Added :noopener HTML scrubber (Thanks, @tastycode!) * Support `data` URIs with the following media types: text/plain, text/css, image/png, image/gif, image/jpeg, image/svg+xml. #101, #120. (Thanks, @mrpasquini!) -Bugfixes: +### Bugfixes: * The :unprintable scrubber now scrubs unprintable characters in CDATA nodes (like `