- Core: Disallow event attribute bindings in host bindings unconditionally, tightening security.
- Core: Validate security-sensitive attributes in i18n bindings to prevent injection attacks.
- Platform Server: Ensure URLs have a trailing slash on origin parsing for consistent handling.