Skip to content
CAI
Software that uses CAICheck a score

rgrove/sanitize

64.6

Adequate · 19 September 2026

1.8k

lines of production code

Ruby

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

Sanitize is a Ruby library designed to clean and sanitize HTML content and inline CSS stylesheets. It leverages Nokogiri for parsing and Crass for CSS validation, employing a modular transformer architecture to enforce strict security allowlists and prevent code injection. The system provides configurable sanitization profiles that handle elements, attributes, and protocols while ensuring deep configuration immutability.

Behavioural changes

Migrate HTML parsing from Hpricot to Nokogiri

The library has switched its underlying HTML parser from Hpricot to Nokogiri (specifically using Nokogiri::HTML5). This change updates the core parsing logic in lib/sanitize.rb, replacing Hpricot-specific calls with Nokogiri equivalents for both document and fragment sanitization. The public API methods have been renamed for clarity (e.g., \clean\ is now \fragment\, \clean\_document\ is now \document\), with aliases provided for backward compatibility. This migration also introduces new transformer-based architecture for cleaning elements, comments, doctypes, and CDATA, and adds support for advanced CSS sanitization via the Crass library.

lib · high confidence

Refactored sanitization into modular transformers with enhanced security and configuration options

The sanitization engine has been restructured into a set of dedicated transformers (CleanCDATA, CleanComment, CleanCSS, CleanDoctype, CleanElement) to improve maintainability and performance. This change introduces stricter security measures, including a workaround for libxml2 code injection vulnerabilities in attributes like href and src, and the removal of potentially dangerous elements such as noscript and meta tags with non-UTF-8 charsets. Users gain new configuration capabilities, such as the :allow\doctype setting to control DOCTYPE handling, support for arbitrary HTML5 data-\ attributes, and the ability to specify :remove\_contents as an array of specific element symbols. Additionally, CSS sanitization is now handled by dedicated classes that enforce allowlists on both style attributes and style elements, with improved escaping to prevent premature closure of style tags.

lib/sanitize/transformers · high confidence

Sanitize 7.0.0: Deep config freezing and new CSS sanitization engine

This release introduces Sanitize 7.0.0, featuring a new \Sanitize::CSS\ class that leverages the Crass library to sanitize inline CSS properties and full stylesheets, including support for at-rules and protocol allowlisting. The configuration system has been hardened by deeply freezing built-in configs to prevent accidental or malicious alteration, and the \Config.merge\ method now safely handles deep merging while converting arrays to sets for better performance and syntax. Additionally, legacy output configuration options (\:output\ and \:output\_encoding\) have been removed.

lib/sanitize · high confidence

Sanitize 7.0.0: Drops support for older Ruby versions and updates tooling

This release increments the major version to 7.0.0 because support for end-of-life Ruby versions has been dropped; Ruby 3.1.0 is now the minimum supported version. The project has also modernized its development tooling by replacing the legacy Rakefile and RDoc-based documentation with Standard Ruby for code style, YARD for documentation generation, and Minitest for testing, while removing the Hpricot dependency in favor of Nokogiri.

(repo-wide) · high confidence

Sanitize configs are now frozen and use relative URL support

The built-in sanitization configurations (Basic, Relaxed, Restricted, and the new Default) are now deeply frozen to prevent accidental or malicious modification at runtime. Additionally, the Basic and Relaxed configs have been updated to allow relative URLs (via the :relative protocol specifier) in attributes like href, cite, and src, and the Relaxed config now includes a broader set of HTML5 elements, attributes, and CSS properties.

lib/sanitize/config · high confidence

Test coverage

Migrate test suite to Minitest

The test suite has been migrated from the Bacon testing framework to Minitest. This change replaces the legacy \test/spec\_sanitize.rb\ and \test/.bacon\ files with a comprehensive suite of new Minitest specs (e.g., \test/test\_clean\_comment.rb\, \test/test\_malicious\_html.rb\, \test/test\_transformers.rb\), ensuring that the library's sanitization logic, configuration handling, and transformer behaviors are verified using the modern Minitest runner.

test · high confidence

Dependencies

Sanitize gem requires Ruby 3.1+ and updates core dependencies

The Sanitize gem now requires Ruby 3.1.0 or later and enforces stricter dependency versions: Nokogiri must be at least version 1.16.8, and Crass is locked to the 1.0.2 series. Development tooling has been standardized with specific versions for Minitest (5.27.0), Rake (13.2.1), and Rubocop plugins, while the gemspec now explicitly requests Multi-Factor Authentication for publishing.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 65.

Lenses

  • Code Health 100
  • Architecture 69
  • Maturity 55
  • Readiness 62
  • Security 100

Changes since last survey

  • 300 commits — 282 feature/other, 18 fixes

By area

  • (root) — 166 commits
  • lib/sanitize — 56 commits
  • (repo) — 29 commits
  • lib/sanitize.rb — 17 commits
  • .github/workflows — 14 commits
  • benchmark/benchmark.rb — 4 commits
  • test/test_malicious_html.rb — 4 commits
  • benchmark/html — 2 commits
  • test/common.rb — 2 commits
  • test/test_sanitize.rb — 2 commits
  • test/test_clean_css.rb — 1 commit
  • test/test_clean_doctype.rb — 1 commit
  • test/test_malicious_css.rb — 1 commit
  • test/test_parser.rb — 1 commit

Notable commits

  • fix: Fix gemspec.
  • fix: Fix incorrect parsing of certain selectors inside a CSS @media block.
  • fix: Fix keyword parameter warnings in Ruby 2.7.0-dev
  • fix: Fix malicious expression injection using a carefully placed comment.
  • fix: Fix sanitization bypass in HTML foreign content
  • fix: Fix some Markdown syntax issues
  • fix: Fix style attributes not being sanitized unless <style> elements were also whitelisted.
  • fix: Fix warning and note styling that GitHub broke
  • fix: Fix warning in Ruby 2.7+
  • fix: Merge pull request #235 from flavorjones/flavorjones-234-readme-fix
  • fix: fix: Don't treat :remove_contents as true when it's an Array
  • fix: fix: Prevent code injection due to improper escaping in libxml2 >= 2.9.2
  • fix: fix: Strip null bytes before passing input to Nokogumbo
  • fix: fix: Unbreak tests when using Nokogiri 1.10.2
  • fix: fix: Update tests to allow new Nokogumbo attribute quoting behavior
  • fix: fix: Update tests to always expect a modern HTML doctype
  • fix: fix: Work around a Nokogumbo 1.4.9 change that allows invalid doctypes.
  • fix: fix: set the DOCTYPE by removing the DTD and creating a new one
  • change: :lipstick:
  • change: :lipstick:
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

rgrove/sanitize was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 91839b0bb95aac86598f49e1393c81845824a420 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.