github akitaonrails/FrankMD v0.3.6

4 hours ago

v0.3.6

Released: 2026-06-27

Changes since v0.3.5 (d67781d..55e3db8).

Security

  • crass 1.0.6 -> 1.0.7 (transitive): four CVEs in the CSS parser used by sanitize / loofah — SystemStackError from deeply-nested blocks/functions, ReDoS-style CPU/memory blow-up on large numeric exponents, superlinear CPU consumption on non-ASCII characters, and another SystemStackError from a large number of adjacent CSS comments.
  • faraday 2.14.2 -> 2.14.3 (transitive): uncontrolled recursion in NestedParamsEncoder allows stack-exhaustion DoS via deeply-nested query parameters.

Infrastructure

  • Bumped actions/cache v4 -> v6 in ci.yml.

Test Coverage

  • 450 Ruby tests, 1,393 JavaScript tests (1,843 total) — unchanged from v0.3.5.

Don't miss a new FrankMD release

NewReleases is sending notifications on new releases.