[Yahoo-eng-team] [Bug 1721193] Re: Outdated and vulnerable versions of Javascript libraries

2021-02-18 Thread Akihiro Motoki
Horizon uses xstatic-jquery 1.12.4.1 since Sep 26 2018. 1.12.4 is the latest jquery release. As Mathias commented above, the maintenance of xstatic-jquery is decoupled with horizon, but horizon is responsible for making horizon work with the latest stable of jquery 1.x series at least. We now

[Yahoo-eng-team] [Bug 1721193] Re: Outdated and vulnerable versions of Javascript libraries

2021-02-17 Thread Jeremy Stanley
I've set our security advisory task for this to Won't Fix as it's a class C2 report per our taxonomy (A vulnerability, but not in OpenStack supported code, e.g., in a dependency): https://security.openstack.org /vmt-process.html#incident-report-taxonomy ** Changed in: ossa Status: