The first front-end commit fixes a real hole: innerHTML would run a title such as <img src=x onerror=alert(1)> as script. The fix should reach main now, before the search box is reviewed, and git cherry-pick copies one commit's change onto the current branch:
git cherry-pick -x ui-search~1
git log -1 --format='%h %ad%n%b' --date=format:%H:%MOutput
[main 3dfdfa3] Escape catalog fields instead of using innerHTML Date: Wed Sep 23 11:20:00 2026 +0800 1 file changed, 5 insertions(+), 3 deletions(-) 3dfdfa3 11:20 (cherry picked from commit 92b3d184c43bc6e99eb198d2d811945e0a78fbb7)
Under the hood this is a three-way merge whose base is the picked commit's parent. The copy keeps the author date (11:20) but gets a new hash, and -x records its origin. After a conflict, resolve and run git cherry-pick --continue. Use it to carry fixes to release branches (Release and Hotfix Branches), not as a routine way to move work, since every copy duplicates a commit.