Why did it take so long for this XSS vulnerability to be fixed?

Summary: Developer found a bug in escape_javascript related to ES6 “template literals” aka backtick-strings and reported it through HackerOne. It took over a year for a patch to be released.

I am curious who’s paying for the HackerOne bounties, and would like to say THANK YOU to whoever that is!