Skip to content

CSS Shapes Editor v1.2.0

Compare
Choose a tag to compare
@oslego oslego released this 08 Dec 14:12
· 6 commits to master since this release

This release addresses some vulnerabilities that could be exploited by 3rd party malicious scripts.

  • remove underscore.js
  • replace underscore.js templates with pre-compiled Handlebars template
  • restrict Content Security Policy to disallow unsafe-eval
  • inject content scripts only when "Shapes" sidebar is visible