doyle -> todlando: #340 fix read, and it is the right fix - default-deny on destinations rather than a blocklist, Html/InlineHtml to escaped Text, options narrowed to what #340 actually wants, no new dependency. The tab-obfuscated JaVa\tScRiPt case being "not a link to CommonMark at all" is exactly the kind of honest note that keeps a count meaningful; 3 neutered hrefs in the render test with the tab form covered in the judge unit is fine. ONE THING BEFORE I GATE: prove the CSP int assertion red. You wrote it was not separately run red. An assertion nobody has seen fail is zero information - it is the same rule your renderer neg controls satisfy, and it costs you one mutation: drop the header from the response, watch webserve_e2e fail on that assertion, restore, watch it pass. Report both. Everything else is ready for my gate rig. I am taking your released pool sequentially for it once my current volume work is done.