Skip to content

build: release version 2.0.14 [skip ci]

f93d45f
Select commit
Loading
Failed to load commit list.
Merged

[Auto release] release 2.0.14 #4425

build: release version 2.0.14 [skip ci]
f93d45f
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / CodeQL succeeded Jan 21, 2026 in 2s

12 new alerts including 12 medium severity security vulnerabilities

New alerts in code changed by this pull request

Security Alerts:

  • 12 medium

Alerts not introduced by this pull request might have been detected because the code changes were too large.

See annotations below for details.

View all branch alerts.

Annotations

Check warning on line 23 in packages/block-vchart/block/vchart/index.js

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete HTML attribute sanitization Medium

Cross-site scripting vulnerability as the output of
this final HTML sanitizer step
may contain double quotes when it reaches this attribute definition.

Check warning on line 23 in packages/block-vchart/block/vchart/index.js

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete HTML attribute sanitization Medium

Cross-site scripting vulnerability as the output of
this final HTML sanitizer step
may contain double quotes when it reaches this attribute definition.

Check warning on line 23 in packages/block-vchart/block/vchart/index.js

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete HTML attribute sanitization Medium

Cross-site scripting vulnerability as the output of
this final HTML sanitizer step
may contain double quotes when it reaches this attribute definition.

Check warning on line 23 in packages/lark-vchart/src/vchart/index.js

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete HTML attribute sanitization Medium

Cross-site scripting vulnerability as the output of
this final HTML sanitizer step
may contain double quotes when it reaches this attribute definition.

Check warning on line 23 in packages/lark-vchart/src/vchart/index.js

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete HTML attribute sanitization Medium

Cross-site scripting vulnerability as the output of
this final HTML sanitizer step
may contain double quotes when it reaches this attribute definition.

Check warning on line 23 in packages/lark-vchart/src/vchart/index.js

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete HTML attribute sanitization Medium

Cross-site scripting vulnerability as the output of
this final HTML sanitizer step
may contain double quotes when it reaches this attribute definition.

Check warning on line 23 in packages/tt-vchart/src/vchart/index.js

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete HTML attribute sanitization Medium

Cross-site scripting vulnerability as the output of
this final HTML sanitizer step
may contain double quotes when it reaches this attribute definition.

Check warning on line 23 in packages/tt-vchart/src/vchart/index.js

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete HTML attribute sanitization Medium

Cross-site scripting vulnerability as the output of
this final HTML sanitizer step
may contain double quotes when it reaches this attribute definition.

Check warning on line 23 in packages/tt-vchart/src/vchart/index.js

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete HTML attribute sanitization Medium

Cross-site scripting vulnerability as the output of
this final HTML sanitizer step
may contain double quotes when it reaches this attribute definition.

Check warning on line 23 in packages/wx-vchart/miniprogram/src/vchart/index.js

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete HTML attribute sanitization Medium

Cross-site scripting vulnerability as the output of
this final HTML sanitizer step
may contain double quotes when it reaches this attribute definition.

Check warning on line 23 in packages/wx-vchart/miniprogram/src/vchart/index.js

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete HTML attribute sanitization Medium

Cross-site scripting vulnerability as the output of
this final HTML sanitizer step
may contain double quotes when it reaches this attribute definition.

Check warning on line 23 in packages/wx-vchart/miniprogram/src/vchart/index.js

See this annotation in the file changed.

Code scanning / CodeQL

Incomplete HTML attribute sanitization Medium

Cross-site scripting vulnerability as the output of
this final HTML sanitizer step
may contain double quotes when it reaches this attribute definition.