Skip to content

Release [Stage to Main] - #151

Merged
JasonHowellSlavin merged 5 commits into
mainfrom
stage
Apr 27, 2026
Merged

Release [Stage to Main]#151
JasonHowellSlavin merged 5 commits into
mainfrom
stage

Conversation

Brandon32 and others added 3 commits April 21, 2026 09:42
The milolibs query param was interpolated directly into template
literals used for dynamic import()s, letting an attacker point module
loading at an arbitrary origin and execute JS in the page context.

Add a strict whitelist (^[a-zA-Z0-9_-]+$) and throw on invalid input
in head.html and scripts/scripts.js.

Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
@aem-code-sync

aem-code-sync Bot commented Apr 23, 2026

Copy link
Copy Markdown

Hello, I'm the AEM Code Sync Bot and I will run some actions to deploy your branch and validate page speed.
In case there are problems, just click a checkbox below to rerun the respective action.

  • Re-run PSI checks
  • Re-sync branch
Commits

@aem-code-sync

aem-code-sync Bot commented Apr 23, 2026

Copy link
Copy Markdown
Page Scores Audits Google
📱 /?martech=off PERFORMANCE A11Y SEO BEST PRACTICES SI FCP LCP TBT CLS PSI
🖥️ /?martech=off PERFORMANCE A11Y SEO BEST PRACTICES SI FCP LCP TBT CLS PSI

@JasonHowellSlavin
JasonHowellSlavin merged commit cafc4c0 into main Apr 27, 2026
13 of 14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants