Skip to content

feat(core): clip-model hf- ids minted at parse, emitted as data-hf-id (R1) - #1270

Merged
vanceingalls merged 4 commits into
mainfrom
06-07-feat_core_clip-model_hf-_ids_minted_at_parse_emitted_as_data-hf-id_r1_
Jun 9, 2026
Merged

vanceingalls merged 4 commits into
mainfrom
06-07-feat_core_clip-model_hf-_ids_minted_at_parse_emitted_as_data-hf-id_r1_

test(core): update htmlParser tests for R1 hf- id minting

cafc27f
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / CodeQL failed Jun 9, 2026 in 2s

6 new alerts including 1 high severity security vulnerability

New alerts in code changed by this pull request

Security Alerts:

  • 1 high
  • 5 medium

See annotations below for details.

View all branch alerts.

Annotations

Check failure on line 162 in packages/core/src/parsers/htmlParser.ts

See this annotation in the file changed.

Code scanning / CodeQL

DOM text reinterpreted as HTML High

DOM text
is reinterpreted as HTML without escaping meta-characters.

Check warning on line 371 in packages/core/src/generators/hyperframes.ts

See this annotation in the file changed.

Code scanning / CodeQL

Unsafe HTML constructed from library input Medium

This HTML construction which depends on
library input
might later allow
cross-site scripting
.

Check warning on line 371 in packages/core/src/generators/hyperframes.ts

See this annotation in the file changed.

Code scanning / CodeQL

Unsafe HTML constructed from library input Medium

This HTML construction which depends on
library input
might later allow
cross-site scripting
.

Check warning on line 377 in packages/core/src/generators/hyperframes.ts

See this annotation in the file changed.

Code scanning / CodeQL

Unsafe HTML constructed from library input Medium

This HTML construction which depends on
library input
might later allow
cross-site scripting
.
This HTML construction which depends on
library input
might later allow
cross-site scripting
.
This HTML construction which depends on
library input
might later allow cross-site scripting.
This HTML construction which depends on
library input
might later allow cross-site scripting.
This HTML construction which depends on
library input
might later allow cross-site scripting.
This HTML construction which depends on
library input
might later allow cross-site scripting.
This HTML construction which depends on
library input
might later allow cross-site scripting.
This HTML construction which depends on
library input
might later allow cross-site scripting.
This HTML construction which depends on
library input
might later allow cross-site scripting.
This HTML construction which depends on
library input
might later allow cross-site scripting.
This HTML construction which depends on
library input
might later allow cross-site scripting.
This HTML construction which depends on
library input
might later allow cross-site scripting.
This HTML construction which depends on library input might later allow
cross-site scripting
.
This HTML construction which depends on library input might later allow
cross-site scripting
.
This HTML construction which depends on library input might later allow cross-site scripting.
This HTML construction which depends on library input might later allow cross-site scripting.
This HTML construction which depends on library input might later allow cross-site scripting.
This HTML construction which depends on library input might later allow cross-site scripting.
This HTML construction which depends on library input might later allow cross-site scripting.
This HTML construction which depends on library input might later allow cross-site scripting.
This HTML construction which depends on library input might later allow cross-site scripting.
This HTML construction which depends on library input might later allow cross-site scripting.
This HTML construction which depends on library input might later allow cross-site scripting.
This HTML construction which depends on library input might later allow cross-site scripting.

Check warning on line 382 in packages/core/src/generators/hyperframes.ts

See this annotation in the file changed.

Code scanning / CodeQL

Unsafe HTML constructed from library input Medium

This HTML construction which depends on
library input
might later allow
cross-site scripting
.

Check warning on line 385 in packages/core/src/generators/hyperframes.ts

See this annotation in the file changed.

Code scanning / CodeQL

Unsafe HTML constructed from library input Medium

This HTML construction which depends on
library input
might later allow
cross-site scripting
.
This HTML construction which depends on
library input
might later allow
cross-site scripting
.
This HTML construction which depends on
library input
might later allow
cross-site scripting
.
This HTML construction which depends on
library input
might later allow cross-site scripting.
This HTML construction which depends on
library input
might later allow cross-site scripting.
This HTML construction which depends on
library input
might later allow cross-site scripting.
This HTML construction which depends on
library input
might later allow cross-site scripting.
This HTML construction which depends on
library input
might later allow cross-site scripting.
This HTML construction which depends on
library input
might later allow cross-site scripting.
This HTML construction which depends on
library input
might later allow cross-site scripting.
This HTML construction which depends on
library input
might later allow cross-site scripting.
This HTML construction which depends on
library input
might later allow cross-site scripting.