CVE-2016-9318
hobbsenigma opened this issue · 1 comments
hobbsenigma commented
Can you comment on whether rails-dom-testing uses nokogiri in a secure way, per sparklemotion/nokogiri#1582? Best practice might be to add a section to the readme, as loofah did: flavorjones/loofah#141 (see flavorjones/loofah#140 for discussion).
rafaelfranca commented
This gem uses nokogiri's default. We are not going add a section to the readme for this specific issue since this can't affect this gem given we use nokogiri's default.