
The HTML Sanitizer API
Browser-native XSS-safe HTML insertion without DOMPurify or other libraries.
Web Standards
Daily web platform news

Browser-native XSS-safe HTML insertion without DOMPurify or other libraries.

A look at the TC39 ShadowRealm proposal for isolating JavaScript in clean execution contexts.

Five approaches compared with their caching and CORS trade-offs.

A web component for isolated code sandboxes without third-party embeds.

An HTML-and-CSS-first library for building web components that hydrate with JS.

Import attributes syntax now works in browsers and runtimes without bundlers.

Retrofitting AgnosticUI with ElementInternals and form validation.

From TC39 proposal to Stage 4, with a shared Rust implementation across engines.

A spec-compliant JavaScript implementation that works across all browsers.

Component model could remove JS glue, simplify loading, and speed up web API access.

React 19, CRA deprecation, CVEs and RSC debates, and AI tooling shaping the ecosystem.

LLM can fix symptoms fast, but it still struggles with root causes.