-
Notifications
You must be signed in to change notification settings - Fork 1.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Security] Bump jquery from 3.4.1 to 3.5.0 in /components #2169
[Security] Bump jquery from 3.4.1 to 3.5.0 in /components #2169
Conversation
The error is coming from this javascript piece loaded on every page. I think it's to keep the small help text popups alive when the user scrolls over the helptext themselves:
|
XSS in versions < 3.5.0: https://snyk.io/vuln/SNYK-JS-JQUERY-565129 |
Issue confirmed by bootstrap / jquery teams: twbs/bootstrap#30553 To be fixed in jquery 3.5.1 |
I don't think we can say ignore minor version to dependabot because that would ignore 3.5.1 etc as well? So let's just wait a couple of days until 3.5.1 arrives :-) |
@dependabot close |
We've just been alerted that this update fixes a security vulnerability: Sourced from The GitHub Security Advisory Database.
|
We've just been alerted that this update fixes a security vulnerability: Sourced from The GitHub Security Advisory Database.
|
Bumps [jquery](https://github.com/jquery/jquery) from 3.4.1 to 3.5.0. - [Release notes](https://github.com/jquery/jquery/releases) - [Commits](jquery/jquery@3.4.1...3.5.0) Signed-off-by: dependabot-preview[bot] <[email protected]>
as in #2805 we should get a new PR for jquery 3.5.1 and according to github support we need to reopen this old PR to get dependabot to do that. sounds crazy but let's see what happens. |
e6693b0
to
8480a05
Compare
@dependabot reopen |
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
@dependabot reopen |
Superseded by #2829. |
Bumps jquery from 3.4.1 to 3.5.0.
Commits
7a0a850
3.5.08570a08
Release: Update AUTHORS.txtda3dd85
Ajax: Do not execute scripts for unsuccessful HTTP responses065143c
Ajax: Overwrite s.contentType with content-type header value, if any1a4f10d
Tests: Blacklist one focusin test in IE9e15d6b
Event: Use only one focusin/out handler per matching window & document966a709
Manipulation: Skip the select wrapper for <option> outside of IE 91d61fd9
Manipulation: Make jQuery.htmlPrefilter an identity function04bf577
Selector: Update Sizzle from 2.3.4 to 2.3.57506c9c
Build: Resolve Travis config warningsMaintainer changes
This version was pushed to npm by mgol, a new releaser for jquery since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)@dependabot badge me
will comment on this PR with code to add a "Dependabot enabled" badge to your readmeAdditionally, you can set the following in the
.dependabot/config.yml
file in this repo: