-
Notifications
You must be signed in to change notification settings - Fork 407
Issue a security advisory for versions < 4.4.0 #275
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Comments
Ping @carlosantoniodasilva since you prepped the release |
bump -- the currently bundled versions of jQuery have security vulnerabilities as well. |
@waissbluth do you have links, please? @jonleighton my apologies, this totally fell off my radar, but I'll see what I can do. |
@carlosantoniodasilva I realize now that jQuery 1 and 2 are no longer being patched so even though there are vulnerabilities there no minor version to upgrade to. thanks |
@waissbluth thanks. It looks like someone sent a PR to update the libraries shipped with jquery-rails with those patches: #281, maybe that's something we can do. |
The latest 4.4.0 release bumps the jQuery version to fix a security vulnerability. Issuing a GitHub security advisory for this project would enable GitHub's security tooling to pick up that users on earlier versions have a vulnerable dependency.
The text was updated successfully, but these errors were encountered: