delphidabbler / codesnip

A code bank designed with Pascal in mind
https://delphidabbler.com/software/codesnip
Other
110 stars 33 forks source link

Potential XSS vulnerability in jQuery #107

Closed delphidabbler closed 1 year ago

delphidabbler commented 1 year ago

This issue relates to dependabot alert 1 which refers to a moderate level vulnerability in jQuery.

This only affects the easter egg.

delphidabbler commented 1 year ago

It will be too much effort to update jQuery from v1.x to v3.x, but the alert suggests a workaround that can be used to avoid updating. Use that.

delphidabbler commented 1 year ago

Fixed by applying dependabot workaround by merge commit 282b50d55f8f1636247d6cb42888841fb4a0cb92