"""Turning what members type into HTML.
`html=False` is the whole security model, and it is worth understanding rather
than copying. With raw HTML disabled, markdown-it never passes a fragment of
the input through untouched: it emits only the tags its own rules produce, and
everything else is escaped as text. A `