chore: strip advisory IDs from code comments and changelog (#4720)

Per the project's policy of treating security advisory IDs as
secret-like, remove the identifiers embedded in source/test comments
and CHANGELOG entries. Each keeps its human-readable description (and
PR number where present), so traceability is preserved. No logic changes.
This commit is contained in:
jekkos authored and GitHub committed 2026-09-30 15:49:18 +02:00
1 parent 5d56c2cecd
commit 9eaa2f34f3
15 files changed
+25 -25

No files matched your search

+1 -1
View File
@@ -111,7 +111,7 @@ class ItemKitsControllerTest extends CIUnitTestCase
$itemKitId = $this->createItemKit();
$this->loginAsAdmin();
// <svg onload=alert(document.domain)> URL-encoded three times (GHSA-3vpv-jqr3-7256 PoC).
// <svg onload=alert(document.domain)> URL-encoded three times.
// The framework's router decodes this twice before routing; the controller used to apply
// a third urldecode(), turning the remaining %3C.../%3E into a live <svg onload=...> tag.
// With that urldecode() removed, the value must stay percent-encoded text and never