USGS-WiM / SiGLDMS

Data management system for SiGL
Other
0 stars 5 forks source link

Remediate Vulnerability: Vulnerable Javascript Library #244

Closed aaronstephenson closed 3 years ago

aaronstephenson commented 3 years ago

Acunetix scan reports this app is using jQuery 2.2.4 and should be updated.

aaronstephenson commented 3 years ago

This is a "medium" level vulnerability and must be remediated as soon as possible.

esmyers commented 3 years ago

updated to v 3.5.1 and deployed to the server. I removed bower resolutions https://github.com/USGS-WiM/SiGLDMS/commit/77b3b9341948a61fa5102e9d41377c7263660bb0#diff-dedb6c21fdaac9cba4da4afde881ffe5c80f80896274dbf7971d312fc6f5207d and used npm shrinkwrap for graceful-fs 4.2.2 to get the thing working again.