Skip to content

Bump com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer from 20260922.1 to 20260924.2 - #1570

Merged
solomax merged 1 commit into
masterfrom
dependabot/maven/com.googlecode.owasp-java-html-sanitizer-owasp-java-html-sanitizer-20260924.2
Oct 5, 2026
Merged

solomax merged 1 commit into
masterfrom
dependabot/maven/com.googlecode.owasp-java-html-sanitizer-owasp-java-html-sanitizer-20260924.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown
Contributor

Bumps com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer from 20260922.1 to 20260924.2.

Release notes

Sourced from com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer's releases.

Release 20260924.2

Changelog

  • 2e944e7 Release version 20260924.2 (GitHub Actions)
  • b203767 Add the change log entry for 20260924.2 (Jim Manico)
  • 9b3233d Make the denial-of-service invariant promise what can be kept (Jim Manico)
  • dfe357e Take the review: size the churn test for an ordinary heap (Jim Manico)
  • 4c910d3 Take the review: keep the walk's guard, drop the dead growth cap (Jim Manico)
  • f95efad Take the review: say the depth scan's over-count can drop valid CSS (Jim Manico)
  • de57cff Take the review: count open brackets in three ints, not 126 (Jim Manico)
  • cf9567f Take the review: make the depth scan's marking plain to read (Jim Manico)
  • 33e8d34 Prepare for next development version (GitHub Actions)
  • afac176 Record GHSA-x6fc-6qh4-g3wr (Jim Manico)

Contributors

We'd like to thank the following people for their contributions:

  • Jim Manico

Release 20260924.1

Changelog

  • 4fd25f3 Release version 20260924.1 (GitHub Actions)
  • 1231831 Take the review: mark function depths in a plain array, not a BitSet (Jim Manico)
  • 82e9b10 Add the denial-of-service invariant to AGENTS.md (Jim Manico)
  • d0b06bd Drop an unmatched CSS close bracket in constant time (Jim Manico)
  • 8a55b77 Drop CSS declarations that nest functions deeper than sixteen (Jim Manico)
  • a310fe4 Harden release and build verification (Jim Manico)
  • 3b122bb Record GHSA-6rfr-g8xv-xrp3 (Jim Manico)
  • 393d86d Prepare for next development version (GitHub Actions)

Contributors

We'd like to thank the following people for their contributions:

  • Jim Manico
Commits
  • 2e944e7 Release version 20260924.2
  • 78de192 Merge pull request #512 from OWASP/release-notes-20260924-2
  • b203767 Add the change log entry for 20260924.2
  • 05895ea Merge pull request #511 from OWASP/agents-dos-wording
  • 9b3233d Make the denial-of-service invariant promise what can be kept
  • 05ca527 Merge pull request #510 from OWASP/css-scan-cleanups
  • dfe357e Take the review: size the churn test for an ordinary heap
  • 4c910d3 Take the review: keep the walk's guard, drop the dead growth cap
  • f95efad Take the review: say the depth scan's over-count can drop valid CSS
  • de57cff Take the review: count open brackets in three ints, not 126
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer](https://github.com/OWASP/java-html-sanitizer) from 20260922.1 to 20260924.2.
- [Release notes](https://github.com/OWASP/java-html-sanitizer/releases)
- [Commits](OWASP/java-html-sanitizer@release-20260922.1...release-20260924.2)

---
updated-dependencies:
- dependency-name: com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer
  dependency-version: '20260924.2'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Oct 4, 2026
@dependabot
dependabot Bot deployed to CI_DEPLOY October 4, 2026 22:52 Active
@solomax
solomax merged commit 3fbac79 into master Oct 5, 2026
1 check passed
@dependabot
dependabot Bot deleted the dependabot/maven/com.googlecode.owasp-java-html-sanitizer-owasp-java-html-sanitizer-20260924.2 branch October 5, 2026 01:36

This branch was successfully deployed

1 active deployment
CI_DEPLOY — c86e6652 Deployed Oct 4, 2026 by dependabot[bot] via Java 17 Test #1758
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant