-
1.5.4
Stablereleased this
2026-07-01 21:46:52 -07:00 | 2 commits to main since this releasev1.5.4 - Security fix: HTML injection in notifications
escape_markdown()escaped[]()*_\`` but not</>`, so raw HTML tags in attacker-controlled commit messages, issue/PR/comment/review/release bodies, or titles rendered as live masked phishing links on Telegram and HTML-format email destinations (both default to HTML rendering). Not exploitable on Discord/Slack/Mattermost/Matrix/MSTeams/Rocket.Chat.Fix:
</>now entity-encoded (</>) instead of backslash-escaped, since python-markdown doesn't honor\<as an escape.Upgrade recommended, especially if you notify via Telegram or email.
Downloads
-
Source code (ZIP)
3 downloads
-
Source code (TAR.GZ)
3 downloads
-
Source code (ZIP)