mraible opened a new pull request, #196: URL: https://github.com/apache/roller/pull/196
Follows up on the jQuery work in #185 by getting rid of the vulnerable jQuery copies Roller still ships outside the admin UI (which is already on the jQuery 3.7.1 webjar). - The gaurav theme bundled jQuery 1.12.4 (CVE-2015-9251, CVE-2019-11358, CVE-2020-11022, CVE-2020-11023) and Bootstrap 3.4.0 (CVE-2019-8331). It now ships jQuery 3.7.1 and Bootstrap 3.4.1, taken unmodified from the official webjars. The old files were unmodified 3.4.0 releases, and the file names are unchanged, so the templates and `theme.xml` stay as they are. - `roller-ui/scripts/jquery-2.1.1.min.js` is deleted. Nothing in Roller references it. Verified on a fresh `jetty:run` instance with a weblog on the gaurav theme: the page loads jQuery 3.7.1 and Bootstrap 3.4.1, and the navbar collapse toggle and the Categories dropdown, the only Bootstrap plugins the theme uses, work at phone and desktop widths with no script errors. Weblogs that customized gaurav keep their own copies of these files. Bootstrap 3 is end of life, so its remaining advisories (CVE-2024-6485, CVE-2025-1647) have no fixed release; moving gaurav to Bootstrap 5 would be a separate redesign. This doesn't overlap with #156, which removes basicmobile's CDN jQuery 2.1.1 and jQuery Mobile. Once both land, Roller no longer ships or references jQuery 1.x or 2.x. The admin UI's move to jQuery 4.0 is left for after #156, since it touches `head.jsp`. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
