jquery-rails icon indicating copy to clipboard operation
jquery-rails copied to clipboard

Issue a security advisory for versions < 4.4.0

Open jonleighton opened this issue 4 years ago • 5 comments

The latest 4.4.0 release bumps the jQuery version to fix a security vulnerability. Issuing a GitHub security advisory for this project would enable GitHub's security tooling to pick up that users on earlier versions have a vulnerable dependency.

jonleighton avatar Jun 08 '20 00:06 jonleighton

Ping @carlosantoniodasilva since you prepped the release

jonleighton avatar Jun 08 '20 00:06 jonleighton

bump -- the currently bundled versions of jQuery have security vulnerabilities as well.

waissbluth avatar Mar 02 '21 03:03 waissbluth

@waissbluth do you have links, please?

@jonleighton my apologies, this totally fell off my radar, but I'll see what I can do.

carlosantoniodasilva avatar Mar 31 '21 01:03 carlosantoniodasilva

@carlosantoniodasilva I realize now that jQuery 1 and 2 are no longer being patched so even though there are vulnerabilities there no minor version to upgrade to. thanks

waissbluth avatar Apr 01 '21 19:04 waissbluth

@waissbluth thanks.

It looks like someone sent a PR to update the libraries shipped with jquery-rails with those patches: https://github.com/rails/jquery-rails/pull/281, maybe that's something we can do.

carlosantoniodasilva avatar Apr 02 '21 13:04 carlosantoniodasilva