Investigate creating @rails/ujs upstream changes to disallow script execution
This is a follow-up to #336138 (closed) and !86799 (merged), about investigating what sort of solution we could create that would be accepted upstream to disallow @rails/ujs from executing fetched scripts.
Note that an issue upstream for changing this was explicitly closed.
An alternative long-term solution might be to switch to a drop-in replacement, which #361765 is about.
Edited by Mark Florian