Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Issue a security advisory for versions < 4.4.0 #275

Open
jonleighton opened this issue Jun 8, 2020 · 5 comments
Open

Issue a security advisory for versions < 4.4.0 #275

jonleighton opened this issue Jun 8, 2020 · 5 comments

Comments

@jonleighton
Copy link
Member

jonleighton commented Jun 8, 2020

The latest 4.4.0 release bumps the jQuery version to fix a security vulnerability. Issuing a GitHub security advisory for this project would enable GitHub's security tooling to pick up that users on earlier versions have a vulnerable dependency.

@jonleighton
Copy link
Member Author

Ping @carlosantoniodasilva since you prepped the release

@jonleighton jonleighton changed the title Issue a security advisory for versions <= 4.4.0 Issue a security advisory for versions < 4.4.0 Jun 8, 2020
@waissbluth
Copy link

bump -- the currently bundled versions of jQuery have security vulnerabilities as well.

@carlosantoniodasilva
Copy link
Member

@waissbluth do you have links, please?

@jonleighton my apologies, this totally fell off my radar, but I'll see what I can do.

@waissbluth
Copy link

@carlosantoniodasilva I realize now that jQuery 1 and 2 are no longer being patched so even though there are vulnerabilities there no minor version to upgrade to. thanks

@carlosantoniodasilva
Copy link
Member

@waissbluth thanks.

It looks like someone sent a PR to update the libraries shipped with jquery-rails with those patches: #281, maybe that's something we can do.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants