This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
ReleasePort's take
Moderate signalThe release bumps loofah to 2.25.2 and rails-html-sanitizer to 1.7.1 for security fixes.
Why it matters: Security fact with severity 90 requires immediate patching of the affected dependencies.
Summary
AI summaryBumped loofah and rails-html-sanitizer for security fixes.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Bump loofah to 2.25.2 and rails-html-sanitizer to 1.7.1 (security). Bump loofah to 2.25.2 and rails-html-sanitizer to 1.7.1 (security). Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Refactor | Low |
Migrate bin/setup to mise's declarative bootstrap pipeline. Migrate bin/setup to mise's declarative bootstrap pipeline. Source: llm_adapter@2026-07-16 Confidence: high |
— |
Full changelog
What's Changed
- Migrate bin/setup to mise's declarative bootstrap pipeline by @jeremy in https://github.com/basecamp/fizzy/pull/2977
- Bump loofah to 2.25.2 and rails-html-sanitizer to 1.7.1 (security) by @flavorjones in https://github.com/basecamp/fizzy/pull/2981
Full Changelog: https://github.com/basecamp/fizzy/compare/[email protected]@5a2ba43
Security Fixes
- Bump loofah to 2.25.2 (security fix)
- Bump rails-html-sanitizer to 1.7.1 (security fix)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]