Changes since 7.x-3.21 (3 commits):
The first official release of the Read Only Mode module.
This release addresses #3012113: Messages set during form_alter are not properly sanitised leading to an XSS vulnerability so it is marked as a security update.
The module didn't sufficiently check access to create new paragraph entities which can cause access bypass issues when used in combination with other contributed modules.
See https://www.drupal.org/sa-contrib-2018-073
This release included 3 minor commits that were accidentally omitted with the last 8.x-1.4 release.
Security update. Session Limit - Critical - Insecure Session Management - SA-CONTRIB-2018-072