`markupsafe.escape` always escapes single and double quotes, and escapes them to their numeric values rather than symbolic According to pallets/jinja@f35e28154f, this is for compatibility with HTML 3.2: the only named entities in the HTML 3.2 DTD are `amp`, `gt`, and `lt`. Update tests to match.