chore: strip advisory IDs from code comments and changelog (#4720)

Per the project's policy of treating security advisory IDs as
secret-like, remove the identifiers embedded in source/test comments
and CHANGELOG entries. Each keeps its human-readable description (and
PR number where present), so traceability is preserved. No logic changes.
This commit is contained in:
jekkos authored and GitHub committed 2026-09-30 15:49:18 +02:00
1 parent 5d56c2cecd
commit 9eaa2f34f3
15 files changed
+25 -25

No files matched your search

+2 -2
View File
@@ -103,7 +103,7 @@ class ItemsControllerTest extends CIUnitTestCase
}
/**
* Regression test for GHSA-92cx-fc8x-7wmm: `tax_names[]` containing `<`/`>`
* Regression test: `tax_names[]` containing `<`/`>`
* (the stored-XSS vector) must be rejected by postSave.
*/
public function testPostSaveRejectsMaliciousTaxName(): void
@@ -190,7 +190,7 @@ class ItemsControllerTest extends CIUnitTestCase
}
/**
* Regression test for GHSA-cm7j-957q-8pgg: an attribute definition whose
* Regression test: an attribute definition whose
* `definition_name` contains HTML must be entity-escaped when rendered in the
* items attributes dropdown, not emitted as a live (executable) tag.
*/