Skip to content
CAI
Software that uses CAICheck a score

gjtorikian/html-pipeline

61.4

Adequate · 19 September 2026

1.2k

lines of production code

Ruby

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is an HTML processing library that constructs pipelines to transform and sanitize HTML content. It converts Markdown to HTML and applies a series of node filters to handle tasks such as URL rewriting, asset proxying, syntax highlighting, and mention linking. The core engine relies on the Selma library for DOM parsing and sanitization, replacing previous implementations to enforce stricter security allowlists and improve performance.

How it got here

2012 — HTML Pipeline v3.0.0 migration

4 changes.

This period focused on the major release of HTML-Pipeline v3.0.0, which involved removing legacy sanitization and asset proxying modules in favor of a new architecture. The update introduced breaking changes, including a namespace shift, the removal of several filters, and a switch from Nokogiri to the Selma parser. Comprehensive test suites were added to validate the new pipeline execution flow and security logic.

2013–2022 — Selma migration and Markdown support

9 changes.

The project migrated its HTML processing pipeline to the Selma library, rewriting all node filters and the sanitization engine to leverage its DOM parsing capabilities. This period also introduced a new MarkdownFilter using Commonmarker and significantly expanded test coverage for the updated filtering architecture and dependency management.

Features

Add MarkdownFilter using Commonmarker

A new MarkdownFilter has been added to the HTML pipeline that converts Markdown text into HTML using the Commonmarker library. Users can now pass Commonmarker-specific parse, render, and extension options via the context hash (e.g., context\[:markdown\]\[:parse\]) to customize the conversion behavior.

_lib/html\_pipeline/convert\filter · high confidence

Removals

Removal of legacy GitHub HTML sanitization and asset proxy modules

The \lib/github/html.rb\ module and its associated \Camouflage\ and \Sanitization\ sub-modules have been removed from the codebase. This eliminates the legacy implementation that handled HTML sanitization whitelists (via the Sanitize library) and the asset proxying logic for images (via the Camouflage mixin). Users relying on these specific internal modules for processing user-generated content will no longer have access to these utilities in this location, as the functionality has been refactored into the new \GitHub::HTML::Pipeline\ architecture.

lib/github · high confidence

Behavioural changes

HTML Pipeline v3.2.4: Migration to Selma and New Filter Architecture

The HTML Pipeline library has been updated to version 3.2.4, introducing a significant backend migration to the Selma library for HTML processing. This change restructures the core filtering system with new base classes (\Filter\, \ConvertFilter\, \NodeFilter\, \TextFilter\) and a dedicated \SanitizationFilter\ that enforces a stricter, safer allowlist of HTML elements and attributes. Users benefit from improved security through this refined sanitization logic and the ability to use context-aware filters, while the underlying engine now relies on Selma for rewriting and sanitization tasks.

_lib/html\pipeline · high confidence

HTML pipeline filters rewritten to use Selma for DOM parsing

All node filters in the HTML pipeline (including AbsoluteSource, AssetProxy, Emoji, Https, ImageMaxWidth, Mention, SyntaxHighlight, TableOfContents, and TeamMention) have been rewritten to use the Selma library for DOM selection and manipulation. This change replaces the previous parsing approach, requiring filters to define a \Selma::Selector\ and implement \handle\_element\ or \handle\_text\_chunk\ methods. The core behavior of each filter remains consistent, but the underlying engine for traversing and modifying the HTML tree has shifted to Selma.

_lib/html\_pipeline/node\filter · high confidence

HTML-Pipeline v3.0.0 major release with breaking changes

This release introduces significant breaking changes for users upgrading from v2. The namespace has changed from \HTML::Pipeline\ to \HTMLPipeline\. Several filters have been removed: \AutolinkFilter\ (now handled by Commonmarker), \SanitizationFilter\ (now handled by Selma), \EmailReplyFilter\, and \CamoFilter\. The API for constructing pipelines has changed, requiring instantiated filters and a new \sanitization\_config\ hash. The underlying HTML parsing library has switched from Nokogiri to Selma. Users must update their code to use the new namespace, remove references to deleted filters, and adjust pipeline construction according to the new API.

(repo-wide) · high confidence

Migrate sanitization engine to Selma and restructure filter execution

The HTML processing pipeline now uses the Selma library for sanitization and node filtering, replacing the previous implementation. This change allows sanitization to run independently without node filters, supports 'just text' pipelines where no node processing is needed, and ensures that sanitization-only filters function correctly. The pipeline now passes context to filters at call time and handles odd numbers of NodeFilters, while Zeitwerk is configured to manage filter loading explicitly.

lib · high confidence

Test coverage

Added mocked instrumentation service for testing; Added test coverage for HTML Pipeline node filters; Added tests for HTMLPipeline dependency loading helpers; Added tests for ImageFilter and PlainTextInputFilter; Added tests for MarkdownFilter behavior and configuration; Initial test suite for HTML Pipeline and SanitizationFilter.

Dependencies

html-pipeline 2.22.0: Ruby 3.2+ requirement, Zeitwerk autoloading, and Selma parser

This release raises the minimum Ruby version to 3.2 and introduces Zeitwerk for autoloading, requiring users to bundle filter gem dependencies (such as commonmarker, gemoji, and rouge) separately. The core HTML parsing dependency has switched from Nokogiri to Selma (\~\> 0.4), and the gemspec now includes a post-install message guiding users on the new dependency structure.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 61.

Lenses

  • Code Health 99
  • Architecture 69
  • Maturity 50
  • Readiness 68
  • Security 71

Changes since last survey

  • 300 commits — 284 feature/other, 16 fixes

By area

  • (root) — 80 commits
  • (repo) — 75 commits
  • lib/html_pipeline — 44 commits
  • lib/html — 43 commits
  • .github/workflows — 25 commits
  • test/html_pipeline — 9 commits
  • lib/html_pipeline.rb — 7 commits
  • test/html_pipeline_test.rb — 4 commits
  • test/html — 3 commits
  • gemfiles/rails_3.gemfile — 2 commits
  • vendor/bundle — 2 commits
  • .github/FUNDING.yml — 1 commit
  • .github/dependabot.yml — 1 commit
  • .vscode/settings.json — 1 commit
  • script/generate_changelog — 1 commit
  • test/sanitization_filter_test.rb — 1 commit
  • test/text_filter_test.rb — 1 commit

Notable commits

  • fix: Bugfix: sanitization-only filters should still work
  • fix: Fix custom renderer with unsafe option missing pre lang
  • fix: Fix instance construction
  • fix: Fix link of Rouge CSS Theme
  • fix: Fix one more missing freeze
  • fix: Merge pull request #300 from stanhu/sh-fix-one-more-freeze
  • fix: Merge pull request #341 from kazk/fix-unsafe-custom-renderer-missing-pre-lang
  • fix: Merge pull request #394 from ppworks/fix-readme-2
  • fix: Merge pull request #395 from ppworks/fix-name_error
  • fix: Merge pull request #412 from jeremysmithco/bug-combining-mention-filters
  • fix: Merge pull request #414 from gjtorikian/fix-sanitization-only
  • fix: README.md: Fix example code
  • fix: fix env var name
  • fix: fix releases
  • fix: fix test
  • fix: fix upgrade doc
  • change: 2.2 is ded
  • change: :gem 3.0.1
  • change: :gem: 3.0.0
  • change: :gem: 3.0.2
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

gjtorikian/html-pipeline was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit c99d76dbfe817598387c371af342e25abdccd363 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.