Skip to content

Releases: flavorjones/loofah

v2.2.3

30 Oct 13:03
Compare
Choose a tag to compare

Notably, this release addresses CVE-2018-16468.

v2.2.2

22 Mar 15:11
Compare
Choose a tag to compare

2.2.2 / 2018-03-22

Make public Loofah::HTML5::Scrub.force_correct_attribute_escaping!,
which was previously a private method. This is so that downstream gems
(like rails-html-sanitizer) can use this logic directly for their own
attribute scrubbers should they need to address CVE-2018-8048.

v2.2.1

20 Mar 20:20
Compare
Choose a tag to compare

Notably, this release mitigates CVE-2018-8048.