v0.55.0 required Go 1.25, breaking the Docker build which uses
golang:1.23-alpine. Downgrade to v0.33.0 which only needs Go 1.18
and still provides the html.Parse API we need.
via [HAPI](https://hapi.run)
Co-Authored-By: HAPI <[email protected]>
JS injection fails on sites with strict Content-Security-Policy
(e.g. GitHub). Add golang.org/x/net/html-based server-side rewriting
of URL attributes (href/src/action/etc.) and CSS url() values before
response is sent. Keep JS injection as fallback for dynamic content.
via [HAPI](https://hapi.run)
Co-Authored-By: HAPI <[email protected]>