SECURITY: Sanitize d-popover attributes (PR #13958)

GitHub

This pull request fixes 1 alert when merging a851aacca55a10b1d888a465e6a1d0ce91e3a4e0 into bb2c48b0657f6182b852ab76fc190825df5d2b7f - view on LGTM.com

fixed alerts:

  • 1 for DOM text reinterpreted as HTML