mraible opened a new pull request, #196:
URL: https://github.com/apache/roller/pull/196

   Follows up on the jQuery work in #185 by getting rid of the vulnerable 
jQuery copies Roller still ships outside the admin UI (which is already on the 
jQuery 3.7.1 webjar).
   
   - The gaurav theme bundled jQuery 1.12.4 (CVE-2015-9251, CVE-2019-11358, 
CVE-2020-11022, CVE-2020-11023) and Bootstrap 3.4.0 (CVE-2019-8331). It now 
ships jQuery 3.7.1 and Bootstrap 3.4.1, taken unmodified from the official 
webjars. The old files were unmodified 3.4.0 releases, and the file names are 
unchanged, so the templates and `theme.xml` stay as they are.
   - `roller-ui/scripts/jquery-2.1.1.min.js` is deleted. Nothing in Roller 
references it.
   
   Verified on a fresh `jetty:run` instance with a weblog on the gaurav theme: 
the page loads jQuery 3.7.1 and Bootstrap 3.4.1, and the navbar collapse toggle 
and the Categories dropdown, the only Bootstrap plugins the theme uses, work at 
phone and desktop widths with no script errors.
   
   Weblogs that customized gaurav keep their own copies of these files. 
Bootstrap 3 is end of life, so its remaining advisories (CVE-2024-6485, 
CVE-2025-1647) have no fixed release; moving gaurav to Bootstrap 5 would be a 
separate redesign.
   
   This doesn't overlap with #156, which removes basicmobile's CDN jQuery 2.1.1 
and jQuery Mobile. Once both land, Roller no longer ships or references jQuery 
1.x or 2.x. The admin UI's move to jQuery 4.0 is left for after #156, since it 
touches `head.jsp`.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to