-
Notifications
You must be signed in to change notification settings - Fork 119
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
jquery-3.4.1 contains vulnerabilities please upgrade to 3.5.1 #108
Comments
Hi, thanks for letting us know and we'll upgrade but as these are XSS vulnerabilities you'd need to look at somebody else's malicious code (as that's the user input we got) if that is even affected by this, or am I missing another attack vector here? |
@PragTob It doesn't seem to matter to our vulnerability scanner how it is used. Just that it is there and the code is flagged as vunlerable. :( |
Of course it doesn't matter for it :D So, your problem is more that your security scanner nags you about it than the actual security risk. |
@PragTob hey, if I made a PR to update to jquery 3.5.1 would you accept the patch? |
https://snyk.io/vuln/npm:[email protected]
https://github.com/simplecov-ruby/simplecov-html/blob/main/assets/javascripts/libraries/jquery-3.4.1.js
https://code.jquery.com/jquery-3.5.1.js
The text was updated successfully, but these errors were encountered: