From 38bcc1e9faf31b91c70ccb68b72b6bb7485e7f1b Mon Sep 17 00:00:00 2001 From: Roland Shoemaker Date: Thu, 13 Apr 2023 15:40:44 -0700 Subject: [PATCH] [release-branch.go1.19] html/template: disallow angle brackets in CSS values # AWS EKS Backported To: go-1.18.10-eks Backported On: Wed, 3 May 2023 Backported By: szafreen@amazon.com Backported From: release-branch.go1.19 Source Commit: https://github.com/golang/go/commit/e49282327b05192e46086bf25fd3ac691205fe80 # Original Information Angle brackets should not appear in CSS contexts, as they may affect token boundaries (such as closing a