- From: James M Snell <notifications@github.com>
- Date: Sat, 03 Jan 2026 11:56:48 -0800
- To: whatwg/url <url@noreply.github.com>
- Cc: Subscribed <subscribed@noreply.github.com>
Received on Saturday, 3 January 2026 19:56:52 UTC
jasnell left a comment (whatwg/url#893) A couple of points: 1. We have a responsible disclosure process. If you are convinced that this is an actual security vulnerability, then that process should have been followed. 2. That said, we implement the spec-defined behavior. *If* there's an actual issue here, which I don't believe there is, then this is correctly dealt with in the issue you opened in the whatwg/url repo (https://github.com/nodejs/node/issues/61264). Opening the second issue here is unnecessary. If/when a change is made to the spec we'll pull that change in here. 3. -1 to adding any "strict parsing mode" in the implementation that goes against what the standard says. I recommend closing this issue. If the issue is deemed to be legitimate in the spec issue, then we'll follow up with the appropriate changes at that time. -- Reply to this email directly or view it on GitHub: https://github.com/whatwg/url/issues/893#issuecomment-3707313807 You are receiving this because you are subscribed to this thread. Message ID: <whatwg/url/issues/893/3707313807@github.com>
Received on Saturday, 3 January 2026 19:56:52 UTC