creativetimofficial / ct-material-kit-pro

Premium Bootstrap 4 UI Kit based on Google's Material Design
https://www.creative-tim.com/product/material-kit-pro
128 stars 36 forks source link

Known security vulnerabilities #170

Closed xperseguers closed 4 years ago

xperseguers commented 4 years ago

Hello, I've bought this pro kit about 1 month ago and now that my website is on production, I am trying to enhance bits and bits of various scores (accessibility, speed, ...). One problem I'm currently facing is that the (afaik) current version of the Bootstrap package you use is reported as having known vulnerabilities:

vulnerabilities

Since I needed a fade effect for the carousel, I am already using another package of your extension, according to https://github.com/creativetimofficial/ct-material-kit-pro/issues/159

According to https://github.com/creativetimofficial/ct-material-kit-pro/issues/108 back in July 2018 you were aware of incompatibility with newer versions of Bootstrap 4.1 that you wanted to include in the next update. We are now 1 year after that, what are you plans?

groovemen commented 4 years ago

Hello @xperseguers,

Thank you for your interest in working with our products. Creative Tim board has decided to set this update to be done somewhere at the end of this year or the very start of the next one after we will receive further feedback. You can't just upgrade to the latest Bootstrap version because this product is made over Bootstrap Material Design which has v4.1.1 Hope this information helps you. Please let us know if we can help you with anything else.

All the best,

Stefan