Skip to content

Stop escaping HTML#224

Merged
kzantow merged 1 commit intospdx:mainfrom
kzantow-anchore:fix/stop-html-escaping
Oct 16, 2023
Merged

Stop escaping HTML#224
kzantow merged 1 commit intospdx:mainfrom
kzantow-anchore:fix/stop-html-escaping

Conversation

@kzantow
Copy link
Copy Markdown
Collaborator

@kzantow kzantow commented Sep 21, 2023

This PR modifies the JSON output behavior to prevent HTML escaping within custom MarshalJSON calls. By calling json.Marshal, the behavior is to use the default of escaping HTML characters. This PR introduces a marshal.JSON function that can be used as a drop-in replacement for json.Marshal with HTML escaping disabled.

This prevents things like Author: Keith <keith@example.com> from getting escaped unnecessarily to something like: Author: Keith &lt;keith@example.com&gt;

Depends on #223

lumjjb
lumjjb previously approved these changes Sep 22, 2023
Copy link
Copy Markdown
Collaborator

@lumjjb lumjjb left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

if only we could just set a global flag somewhere, but yea this seems like the best approach for what we have

Signed-off-by: Keith Zantow <kzantow@gmail.com>
@kzantow kzantow force-pushed the fix/stop-html-escaping branch from d4fe9b9 to 8922633 Compare October 10, 2023 17:59
@kzantow kzantow merged commit 7f95b01 into spdx:main Oct 16, 2023
@kzantow kzantow deleted the fix/stop-html-escaping branch October 16, 2023 15:18
cuixq referenced this pull request in google/osv-scanner Apr 17, 2024
[![Mend
Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com)

This PR contains the following updates:

| Package | Type | Update | Change | Age | Adoption | Passing |
Confidence |
|---|---|---|---|---|---|---|---|
| [deps.dev/api/v3](https://togithub.com/google/deps.dev) | require |
digest | `2c48bd5` -> `f6f382d` | | | | |
| [deps.dev/util/maven](https://togithub.com/google/deps.dev) | require
| digest | `2c48bd5` -> `f6f382d` | | | | |
| [deps.dev/util/resolve](https://togithub.com/google/deps.dev) |
require | digest | `2c48bd5` -> `f6f382d` | | | | |
| [deps.dev/util/semver](https://togithub.com/google/deps.dev) | require
| digest | `2c48bd5` -> `f6f382d` | | | | |
| [github.com/spdx/tools-golang](https://togithub.com/spdx/tools-golang)
| require | patch | `v0.5.3` -> `v0.5.4` |
[![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fspdx%2ftools-golang/v0.5.4?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|
[![adoption](https://developer.mend.io/api/mc/badges/adoption/go/github.com%2fspdx%2ftools-golang/v0.5.4?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|
[![passing](https://developer.mend.io/api/mc/badges/compatibility/go/github.com%2fspdx%2ftools-golang/v0.5.3/v0.5.4?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|
[![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fspdx%2ftools-golang/v0.5.3/v0.5.4?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|
| golang.org/x/exp | require | digest | `93d18d7` -> `fe59bbe` | | | | |

---

### Release Notes

<details>
<summary>spdx/tools-golang (github.com/spdx/tools-golang)</summary>

###
[`v0.5.4`](https://togithub.com/spdx/tools-golang/releases/tag/v0.5.4)

[Compare
Source](https://togithub.com/spdx/tools-golang/compare/v0.5.3...v0.5.4)

##### What's Changed

- Stop escaping HTML by [@&#8203;kzantow](https://togithub.com/kzantow)
in
[https://github.com/spdx/tools-golang/pull/224](https://togithub.com/spdx/tools-golang/pull/224)
- Don't create empty `ExcludedFiles` array by
[@&#8203;DmitriyLewen](https://togithub.com/DmitriyLewen) in
[https://github.com/spdx/tools-golang/pull/230](https://togithub.com/spdx/tools-golang/pull/230)
- Add external reference category `OTHER` by
[@&#8203;mcombuechen](https://togithub.com/mcombuechen) in
[https://github.com/spdx/tools-golang/pull/229](https://togithub.com/spdx/tools-golang/pull/229)
- Remove empty packageVerificationCode in 2.2 JSON by
[@&#8203;kzantow](https://togithub.com/kzantow) in
[https://github.com/spdx/tools-golang/pull/223](https://togithub.com/spdx/tools-golang/pull/223)

##### New Contributors

- [@&#8203;mcombuechen](https://togithub.com/mcombuechen) made their
first contribution in
[https://github.com/spdx/tools-golang/pull/229](https://togithub.com/spdx/tools-golang/pull/229)

**Full Changelog**:
spdx/tools-golang@v0.5.3...v0.5.4

</details>

---

### Configuration

📅 **Schedule**: Branch creation - "before 6am on monday" in timezone
Australia/Sydney, Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config help](https://togithub.com/renovatebot/renovate/discussions) if
that's undesired.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Mend
Renovate](https://www.mend.io/free-developer-tools/renovate/). View
repository job log
[here](https://developer.mend.io/github/google/osv-scanner).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy4yOTMuMCIsInVwZGF0ZWRJblZlciI6IjM3LjMwMS40IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=-->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants