Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Update jquery-ui to 1.13.3 and bump gem version to 7.0.1 #156

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
wants to merge 1 commit into from

Conversation

rheaton
Copy link

@rheaton rheaton commented Nov 13, 2024

Compliance scanners are triggered on this gem because of a CVE in jquery UI that was corrected in 1.13.2.

Upgrading to the latest jquery-ui patch version 1.13.3.

jQuery UI Changlogs:

@gabriel-lima
Copy link

@Borzik , @rosenfeld, @joliss , would it be possible to approve this and publish to rubygems? It would be much appreciated, and thank you.

@dil-ecsonka
Copy link

@Borzik , @rosenfeld, @joliss I'm also interested in this fix, especially because of that security fix. Can you review this PR? Thanks in advance!

@Ch1g
Copy link

Ch1g commented Feb 3, 2025

@Borzik , @rosenfeld, @joliss Security fix is also relevant for me and my team. Thank you!

@Routable
Copy link

I presume that jquery-ui-rails has been abandoned at this point, given that this PR has sat untouched for this long.

As others have mentioned, jquery-ui-rails 7.0.0 pins the jQuery UI version to 1.12.1 which currently suffers from a CVE which is triggered by dependabot.

This should be resolved via the PR provided, but I think we will just move away from the gem instead.

@Borzik
Copy link
Contributor

Borzik commented Apr 17, 2025

Superseded by #157 (now merged)

@Borzik Borzik closed this Apr 17, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

6 participants