render_editorjs
render_editorjs copied to clipboard
A modular and customizable Ruby renderer for https://editorjs.io
I've identified a potential **XSS vulnerability** in how `render_editorjs` handles links and possibly other tools, where JavaScript can be injected via the `href` attribute. Specifically, links with the `javascript:` protocol,...
Bumps [rexml](https://github.com/ruby/rexml) from 3.3.9 to 3.4.2. Release notes Sourced from rexml's releases. REXML 3.4.2 - 2025-08-26 Improvement Improved performance. GH-244 GH-245 GH-246 GH-249 GH-256 Patch by NAITOH Jun Raise appropriate...