From a51c679da0e4bfc5f72f5385d1af0c4228d112b2 Mon Sep 17 00:00:00 2001 From: Anupam Mediratta Date: Sat, 12 Sep 2026 01:25:26 +0530 Subject: [PATCH] fix: add output encoding in releaseNotesTab.component.ts (#11535) Co-authored-by: Eugene --- tabby-settings/src/components/releaseNotesTab.component.ts | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/tabby-settings/src/components/releaseNotesTab.component.ts b/tabby-settings/src/components/releaseNotesTab.component.ts index 07825c844..e7404b84f 100644 --- a/tabby-settings/src/components/releaseNotesTab.component.ts +++ b/tabby-settings/src/components/releaseNotesTab.component.ts @@ -1,7 +1,8 @@ /* eslint-disable @typescript-eslint/explicit-module-boundary-types */ import { marker as _ } from '@biesbjerg/ngx-translate-extract-marker' import { marked } from '../../node_modules/marked/lib/marked.esm.js' -import { Component, Injector } from '@angular/core' +import { Component, Injector, SecurityContext } from '@angular/core' +import { DomSanitizer } from '@angular/platform-browser' import { BaseTabComponent, TranslateService } from 'tabby-core' export interface Release { @@ -21,7 +22,7 @@ export class ReleaseNotesComponent extends BaseTabComponent { releases: Release[] = [] lastPage = 1 - constructor (translate: TranslateService, injector: Injector) { + constructor (translate: TranslateService, injector: Injector, private domSanitizer: DomSanitizer) { super(injector) this.setTitle(translate.instant(_('Release notes'))) this.loadReleases(1) @@ -36,7 +37,7 @@ export class ReleaseNotesComponent extends BaseTabComponent { this.releases = this.releases.concat(releases.map(r => ({ name: r.name, version: r.tag_name, - content: marked(r.body), + content: this.domSanitizer.sanitize(SecurityContext.HTML, marked(r.body)) ?? '', date: new Date(r.created_at), }))) this.lastPage = page