Change record status: 
Project: 
Introduced in branch: 
8.0.x
Description: 

Previously \Drupal\Core\Entity\EntityListBuilder::getLabel() returned the escaped entity label and added it to the safe list. This method has been deprecated and no longer escapes or marks the label as safe. If the EntityListBuilder implementation is just preparing output for Twig no changes need to be made since Twig will autoescape the label for you. If \Drupal\Core\Entity\EntityListBuilder::getLabel() is being used to prepare output for JSON or something else, then, when the output is being prepared \Drupal\Component\Utility\Html::escape() should be called. Do not do this in an override of \Drupal\Core\Entity\EntityListBuilder::getLabel() as this will cause double escaping.

Related change records

See Twig autoescape enabled and text sanitization APIs updated