pj 8c7470a1a6 fix(web-runtime): use CSS.escape and validate tag-name selectors
The previous cssEscape only handled " and \, leaving newlines/control
chars to break out of attribute string literals. Delegate to the
platform CSS.escape per CSSOM spec.

The `tag` selector branch returned the bare value through cssEscape,
which doesn't prevent pseudo-classes (`*:hover`) from injecting into
the surrounding selector. Add a positive whitelist; values that don't
match a tag-name pattern collapse to a never-matching `:not(*)`.

Also switch class selectors to `[class~="..."]` to remove the only
identifier-context use of cssEscape.
2026-05-03 10:59:06 +07:00
2026-04-25 20:04:29 +07:00
2026-04-25 20:04:29 +07:00
2026-04-25 20:04:29 +07:00
2026-04-25 20:04:29 +07:00

sanderling

Autonomous property-based testing for mobile apps. Specs in TypeScript. Core in Go. Drives the app under test through Maestro.

Alpha. Android emulator only. Full scope in the v0.1.0 roadmap.

Docs

After a sanderling test run, browse traces locally with sanderling inspect. It opens a web UI for stepping through actions, screenshots, snapshots, residual formulas, and exceptions.


sanderling

sanderling, a wading bird that probes the shoreline for bugs that lie beneath.

S
Description
No description provided
Readme Apache-2.0
51 MiB
0 Stars 1 Watchers 0 Forks
Languages
Go 74.6%
TypeScript 15.2%
Kotlin 5.5%
Shell 2.7%
Swift 1%
Other 0.9%