-
Notifications
You must be signed in to change notification settings - Fork 4.2k
fix: upgrade tinymce latest MIT licensed version #41003
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
…o fix/upgrade-tinymce-latest-MIT-version
WalkthroughThis change updates the TinyMCE dependency from version 6.8.3 to 6.8.5 in the client application and modifies the RichTextEditor widget's initialization to enable automatic conversion of unsafe embedded content by setting Changes
Sequence Diagram(s)sequenceDiagram
participant User
participant RichTextEditorComponent
participant TinyMCE
User->>RichTextEditorComponent: Loads editor
RichTextEditorComponent->>TinyMCE: Initialize with config (convert_unsafe_embeds: true)
TinyMCE-->>RichTextEditorComponent: Editor ready with unsafe embed conversion enabled
Possibly related PRs
Suggested labels
Suggested reviewers
Poem
✨ Finishing Touches
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. 🪧 TipsChatThere are 3 ways to chat with CodeRabbit:
SupportNeed help? Create a ticket on our support page for assistance with any issues or questions. Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments. CodeRabbit Commands (Invoked using PR comments)
Other keywords and placeholders
Documentation and Community
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Actionable comments posted: 0
🧹 Nitpick comments (1)
app/client/src/widgets/RichTextEditorWidget/component/index.tsx (1)
433-433
: Enable unsafe embed conversion in TinyMCE
Addingconvert_unsafe_embeds: true
leverages the new feature in 6.8.5 to sanitize embedded content. Consider adding or updating rich-text editor tests to cover embed sanitization scenarios.
📜 Review details
Configuration used: .coderabbit.yaml
Review profile: CHILL
Plan: Pro
⛔ Files ignored due to path filters (1)
app/client/yarn.lock
is excluded by!**/yarn.lock
,!**/*.lock
📒 Files selected for processing (2)
app/client/package.json
(1 hunks)app/client/src/widgets/RichTextEditorWidget/component/index.tsx
(1 hunks)
⏰ Context from checks skipped due to timeout of 90000ms (5)
- GitHub Check: client-build / client-build
- GitHub Check: client-check-cyclic-deps / check-cyclic-dependencies
- GitHub Check: client-lint / client-lint
- GitHub Check: client-unit-tests / client-unit-tests
- GitHub Check: client-prettier / prettier-check
🔇 Additional comments (1)
app/client/package.json (1)
229-229
: Bump TinyMCE to v6.8.5 for MIT license compliance
Upgrading addresses dependabot alerts and ensures we’re on the latest MIT-licensed TinyMCE.
Please verify that the lockfile reflects this change and that CI installs tinymce@6.8.5 successfully.
Description
Fixes
https://github.com/appsmithorg/appsmith/security/dependabot/348
https://github.com/appsmithorg/appsmith/security/dependabot/347
https://github.com/appsmithorg/appsmith/security/dependabot/290
Automation
/ok-to-test tags="@tag.Widget, @tag.TextEditor, @tag.Binding"
🔍 Cypress test results
Tip
🟢 🟢 🟢 All cypress tests have passed! 🎉 🎉 🎉
Workflow run: https://github.com/appsmithorg/appsmith/actions/runs/15773718244
Commit: a11b75e
Cypress dashboard.
Tags:
@tag.Widget, @tag.TextEditor, @tag.Binding
Spec:
Fri, 20 Jun 2025 09:01:44 UTC
Communication
Should the DevRel and Marketing teams inform users about this change?
Summary by CodeRabbit