summaryrefslogtreecommitdiffstats
path: root/3rdparty/htmlpurifier/WHATSNEW
diff options
context:
space:
mode:
Diffstat (limited to '3rdparty/htmlpurifier/WHATSNEW')
-rw-r--r--3rdparty/htmlpurifier/WHATSNEW11
1 files changed, 5 insertions, 6 deletions
diff --git a/3rdparty/htmlpurifier/WHATSNEW b/3rdparty/htmlpurifier/WHATSNEW
index c8ec4f90b..7464cbc35 100644
--- a/3rdparty/htmlpurifier/WHATSNEW
+++ b/3rdparty/htmlpurifier/WHATSNEW
@@ -1,6 +1,5 @@
-HTML Purifier 4.5.0 is a minor bugfix and feature release, containing an
-accumulation of changes over a year. CSS support has been extended to
-support display:inline-block, white-space, underscores in font families,
-page-break-* CSS3 properties (when proprietary is enabled.) We now use
-SHA-1 to identify cached definitions, and the semantics of stacked
-attribute transforms has changed slightly.
+HTML Purifier 4.6.0 is a major security release, fixing numerous bad
+quadratic asymptotics in HTML Purifier's core algorithms. Most users will
+see a decent speedup on large inputs, although small inputs may take
+longer. Additionally, the secure URI munging algorithm has changed to
+do a proper HMAC. There are some other miscellaneous bugfixes as well.