basecamp/trix
43.0
Weak · 1 October 2026
10.7k
lines of production code
JavaScript
primary language
2
measurements over time
What this system is
This system is the Action Text Trix engine, a rich text editor component for Ruby on Rails applications. It provides a modernized, secure editing interface featuring attachment galleries, native form integration, and comprehensive developer debugging tools. The codebase has been fully migrated from CoffeeScript to JavaScript with a robust build pipeline and extensive test coverage.
Features
Add Inspector views for debugging, performance, and document state
The Inspector now includes dedicated views for debugging (with controls for view caching, rendering, parsing, and control elements), document state, performance metrics (tracking render, sync, and garbage collection timings), render/sync counts, selection details (including character-level highlighting), and undo/redo history. These views are registered with the Inspector framework to provide real-time insights into the editor's internal state and performance.
src/inspector/views · high confidence
Add Watchdog inspector for recording and replaying DOM changes
The inspector/watchdog module now includes a complete system for recording and replaying DOM interactions. A new PlayerElement custom element (trix-watchdog-player) allows users to load and play back recordings via a src attribute. The underlying PlayerController and Player classes manage playback logic, while the PlayerView renders the replayed snapshots in an iframe alongside a control bar and event log. Recordings are captured by the Recorder, which listens for input, keypress, and selection change events and captures DOM snapshots using the Serializer, and can be deserialized and replayed using the Deserializer.
src/inspector/watchdog · high confidence
Add developer inspector and debugger tools
New files in src/inspector introduce a client-side debugging interface for Trix. The inspector registers a custom \<trix-inspector\> element that attaches to editors, displaying collapsible views for document structure, input events, mutations, performance, and undo history. A separate debugger module wraps specific controller methods (e.g., in EditorController, ToolbarController) with error handlers that log stack traces and notify listeners, aiding in development and troubleshooting.
src/inspector · high confidence
Attachment editing and gallery filtering capabilities
Users can now edit captions for previewable attachments via a dedicated toolbar and caption editor, with changes persisted through the composition controller. Additionally, a new attachment gallery filter automatically formats sequences of attachments into a gallery layout by applying block attributes, and file attachments are verified before insertion.
src/trix/controllers · high confidence
New development and test assets for local usage
The assets directory now includes an index.html demo page that initializes the Trix editor, displays the generated HTML output in a textarea, and handles file uploads via a development server endpoint. A test.html page is also added to run the QUnit test suite (version 2.19.1). Additionally, a trix.scss entry point is introduced to compile the editor's styles from separate SCSS modules.
assets · high confidence
Removals
Removal of legacy RichText component files
The legacy RichText component implementation, including its CoffeeScript controller and the associated HTML demo page, has been removed from the source code. This change eliminates the previous rich text editing interface and its installation logic, aligning with the project's shift toward the Trix editor.
src · high confidence
Removal of the legacy CoffeeScript rich-text editor implementation
The \src/rich\_text\ directory has been completely removed, eliminating the previous rich-text editing capability built with CoffeeScript. This deletion removes the core components that managed text state and rendering, including the \RichText.Controller\ for handling DOM events, the \RichText.Text\ and \RichText.Piece\ classes for managing text content and attributes, the \RichText.PieceList\ for structural operations, the \RichText.Renderer\ for visual output, and supporting utilities like \RichText.Hash\.
_src/rich\text · high confidence
Security
Sanitize pasted HTML to prevent XSS vulnerabilities
The editor now sanitizes all HTML content during paste operations using DOMPurify with the SAFE\_FOR\_XML option. This change prevents stored and copy-paste XSS attacks by stripping dangerous elements (like script and noscript) and protocols (like javascript:), while ensuring that attachment data serialized in attributes is safely escaped to survive the sanitization process.
src/trix/models · high confidence
Behavioural changes
Action Text Trix engine v2.1.19 with DOMPurify 3.4.13 and XSS fixes
The \action\_text-trix\ Ruby gem has been updated to version 2.1.19, bundling the Trix editor with DOMPurify upgraded to 3.4.13. This release addresses several security vulnerabilities, including stored XSS via the \data-trix-serialized-attributes\ sanitizer bypass, XSS in attachment href rendering, and XSS via \javascript:\ URIs in JSON drag-drop deserialization. It also fixes a bug where pasted attachments were destroyed by DOMPurify and ensures angle brackets in attachment JSON are escaped to survive sanitization. Additionally, the editor now dispatches a \trix-before-render\ event and reads the initial value from HTML content.
_action\text-trix · high confidence
Automatic initialization and expanded public API exposure
The Trix editor now automatically registers its custom elements (trix-toolbar and trix-editor) immediately after import, removing the need for manual initialization in most cases. Additionally, the public Trix object now exposes core modules (config, core, models, views, controllers, observers, operations, elements, filters) as properties, and directly attaches model classes to the Trix namespace for backward compatibility with version 1.
src/trix · high confidence
Centralized configuration system for editor behavior and UI
The editor's settings are now managed through a structured \src/trix/config\ module, replacing previous inline or scattered definitions. This change introduces dedicated configuration files for attachments (defaulting to gallery presentation), block attributes (defining HTML tags for headings, lists, and code), browser-specific input handling (addressing Android/Samsung keyboard quirks), and DOMPurify sanitization (enabling SAFE\_FOR\_XML mode by default). It also exposes configuration for the toolbar HTML, text attributes, file size formatting, and undo intervals, allowing users to inspect and customize these aspects of the editor's behavior and appearance.
src/trix/config · high confidence
Core collection utilities converted to JavaScript
The collection utilities in src/trix/core/collections (Hash, ObjectGroup, ObjectMap, ElementStore) have been converted from CoffeeScript to JavaScript. This change updates the internal data structures used for managing object groups, attribute hashes, and element storage, ensuring they function correctly in the modernized codebase.
src/trix/core/collections · high confidence
Core modules migrated to ES modules with new serialization API
The core library files (basic\_object, object, serialization, utilities) have been converted from CoffeeScript to JavaScript and now use ES module syntax. This migration introduces a new \serializeToContentType\ and \deserializeFromContentType\ API in the serialization module, allowing users to explicitly convert documents to JSON or HTML strings based on content type, replacing the previous implicit serialization behavior.
src/trix/core · high confidence
Inspector templates converted to JavaScript
The inspector template files in src/inspector/templates have been converted from CoffeeScript to JavaScript. This change updates the internal implementation of the inspector's UI rendering logic while maintaining the same user-facing debugging and inspection capabilities.
src/inspector/templates · high confidence
JavaScript migration and text handling improvements in core helpers
The core helper modules have been converted from CoffeeScript to JavaScript, introducing several functional updates. Text input now normalizes lone carriage returns as new lines and escapes angle brackets in attachment JSON to prevent DOMPurify from stripping pasted content. Text direction detection on Chrome is restored by leveraging the \dirName\ property and \:dir\ CSS selector. Additionally, a workaround is included to prevent garbled content and duplicated newlines when using dictation on iOS 18+.
src/trix/core/helpers · high confidence
Migrate core utilities from CoffeeScript to JavaScript
The core utility modules in src/trix/core/utilities, specifically operation.js and utf16\_string.js, have been converted from CoffeeScript to JavaScript. This change includes the addition of an index.js manifest to manage exports and updates the underlying implementation of the Operation class to use native JavaScript Promises instead of the previous CoffeeScript-based approach, while the UTF16String class retains its UCS-2/UTF-16 handling logic in the new language.
src/trix/core/utilities · high confidence
Migrate views from CoffeeScript to JavaScript and harden attachment rendering
The view layer in src/trix/views has been converted from CoffeeScript to JavaScript, introducing several security and behavioral improvements. Attachment rendering now escapes angle brackets in JSON attributes to prevent DOMPurify conflicts and validates hrefs via DOMPurify to mitigate XSS risks. Additionally, the image view now supports custom alt attributes, and block views allow custom HTML attributes when explicitly configured.
src/trix/views · high confidence
Modernized build system and developer tooling
The project has replaced its legacy CoffeeScript and Sprockets-based build pipeline with a modern JavaScript toolchain using Rollup for bundling (producing ESM and UMD formats), Babel for transpilation, and ESLint for code quality. Development and testing now rely on @web/test-runner with Playwright instead of the previous PhantomJS/Karma setup, and the Node.js runtime requirement has been updated to version 18.18.0. These changes improve build performance, enable native ES module support, and provide better test debugging via source maps.
(repo-wide) · high confidence
Native form integration and placeholder support for Trix elements
The Trix editor and toolbar elements now support native HTML form integration via the ElementInternals API, allowing the editor to participate in form validation and submission as a standard form control. Additionally, the editor now displays placeholder text when empty, improving usability for empty states, and the toolbar exposes an \editorElements\ property to programmatically access associated editors.
src/trix/elements · high confidence
New CI, Sass build, and setup scripts; removed legacy rake binstub
The repository now includes three new executable scripts in the bin directory to streamline development and CI workflows. bin/ci runs GitHub Actions workflow linting (actionlint, zizmor) and executes tests, replacing the previous Travis CI setup. bin/sass-build compiles SCSS to CSS using the sass library and supports a watch mode for development, reflecting a switch from node-sass. bin/setup automates the installation of required system tools (actionlint, shellcheck, zizmor via Homebrew), Ruby gems, and npm modules, and configures local development environments including Pow. Additionally, the legacy bin/rake binstub has been removed, as rake is now invoked directly via Bundler.
bin · high confidence
Redesigned editor interface with new attachment galleries and toolbar
The visual appearance of the Trix editor has been significantly updated. The toolbar now uses SVG icons for formatting tools and history actions, with a layout that left-aligns formatting tools and right-aligns history tools, including support for mobile screens. Attachment handling has been overhauled to support galleries (groups of 2 or 4 images) that flexibly wrap and scale, along with a dedicated attachment toolbar for managing captions and metadata. Content styling has also been refined, with improved handling of code blocks (horizontal scrolling instead of wrapping), blockquotes, and headings, while ensuring consistent font sizing and line heights across the editor.
assets/trix/stylesheets · high confidence
Simplified selection change detection and standardized observer exports
The selection change observer now relies exclusively on the native selectionchange API, removing previous checks for DOM range equality to streamline how cursor and selection updates are detected. Additionally, the observers module now uses an index.js manifest to explicitly export the MutationObserver and SelectionChangeObserver classes, providing a cleaner public interface for these components.
src/trix/observers · high confidence
Test coverage
Added system tests for editor accessibility, attachments, and input handling; Added test coverage for CSP nonce handling and JSON string escaping; Added test coverage for the Action Text Trix engine; Added test fixtures for editor accessibility and configuration scenarios; Added unit tests for core models, sanitization, and parsing; New JavaScript test helper utilities for editor testing.
Dependencies
Introduce Ruby gem packaging and modernize build tooling
The project now ships as a dedicated Ruby gem (\action\_text-trix\) with its own \Gemfile\ and \gemspec\, establishing a formal dependency on \railties\ and including test dependencies like \cuprite\ and \minitest\. This replaces the previous root-level Ruby dependencies (\rake\, \sprockets\, \coffee-script\), which have been removed. On the JavaScript side, the build system has been modernized: \node-sass\ is replaced by \sass\, and the project now uses Rollup for bundling, ESLint for linting, and \@web/test-runner\ for testing, with \dompurify\ added as a runtime dependency for HTML sanitization.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 43 → 43 (-0.2)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 39 → 39 (+0.0)
- Architecture 88 → 84 (-3.6)
- Maturity 53 → 53 (+0.0)
- Readiness 52 → 53 (+1.0)
- Security 66 → 74 (+8.4)
- Accessibility 37 → 34 (-2.9)
- Performance 100 (new)
Resolved (5)
- Documentation: no installation or build instructions (README.md)
- Documentation: no licence statement (README.md)
- Documentation: no usage examples (README.md)
- High CVE: [GHSA redacted] (yarn.lock)
- Off-boarding risk: anonymized user #1
New (15)
- Coverage not measured — JavaScript/TypeScript suite
- High CVE: [GHSA redacted] (yarn.lock)
- Low cohesion: LegacyDelegate (LCOM4 4) (action_text-trix/app/assets/javascripts/trix.js)
- Low cohesion: Level0InputController (LCOM4 5) (action_text-trix/app/assets/javascripts/trix.js)
- Low cohesion: Level0InputController (LCOM4 5) (src/trix/controllers/level_0_input_controller.js)
- Low cohesion: PlayerView (LCOM4 4) (src/inspector/watchdog/player_view.js)
- Low vulnerability: [GHSA redacted] (yarn.lock)
- Medium CVE: [GHSA redacted] (yarn.lock)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Off-boarding risk: anonymized user #1
- Projects may be oversized for their cohesion
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
basecamp/trix was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit d7c1298088d97686273e1459975f2c8bdb296b58 — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.