Skip to content
This repository has been archived by the owner on Mar 20, 2024. It is now read-only.

Update Library uglify-js, High Vulnerability #602

Closed
bit-pro-iew-eui opened this issue Nov 29, 2017 · 4 comments
Closed

Update Library uglify-js, High Vulnerability #602

bit-pro-iew-eui opened this issue Nov 29, 2017 · 4 comments
Assignees
Milestone

Comments

@bit-pro-iew-eui
Copy link
Contributor

image

Update to version >2.6.0

@gillerr
Copy link
Contributor

gillerr commented Dec 4, 2017

The project is minified using the latest uglify-js version, i.e. v3.2.0.

uglify-js version 2.4.24 is a dependency of grunt-contrib-uglify v.0.2.7 (latest version is v3.2.1) which itself is a dependency of bootstrap-accessibility-plugin v1.0.2.
bootstrap-accessibility-plugin is a fork, made by Liip, of a fork, made by Antistatique, of the original plug-in. There has been next to no development on either forks of this plug-in for more than 2 years. Also note that this plug-in only apply to Bootstrap version 3 and is irrelevant for Bootstrap 4, so it's not likely that anything will done on this plug-in.

Either Liip has to update their fork of bootstrap-accessibility-plugin to use a more recent version of grunt-contrib-uglify plug-in or we can fork the plug-in to update the dependency ourselves.

@bit-pro-iew-eui bit-pro-iew-eui modified the milestones: 3.3, 3.2 Dec 7, 2017
@bit-pro-iew-eui
Copy link
Contributor Author

Please @gillerr add a list of the affected components, in order to test them

@gillerr
Copy link
Contributor

gillerr commented Dec 7, 2017

  • alert
  • carousel
  • collapse
  • dropdown
  • modal
  • popover
  • tab
  • tooltip

@bit-pro-iew-eui
Copy link
Contributor Author

Ok, no problem detected

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants