powsybl / powsybl.github.io

Powsybl Website
https://www.powsybl.org
Creative Commons Attribution 4.0 International
7 stars 4 forks source link

[CVE-2020-11022] Update jQuery to 3.5.0 #291

Open miovd opened 1 year ago

miovd commented 1 year ago

Please check if the PR fulfills these requirements

What kind of change does this PR introduce? Vulnerability fix https://github.com/powsybl/powsybl.github.io/security/dependabot/1 [CVE-2020-11022] Potential XSS vulnerability in jQuery

olperr1 commented 8 months ago

This PR is ineffective: it only change a comment!

Each component of assets/vendor should be examined since it can be incompatible with the new JQuery version. For instance, the site uses "bootstrap v4.4.1" and I don't think it is compatible (see the v4.4 and v4.5 documentations).

So-Fras commented 7 months ago

Regarding the components present in assets/vendor, I have found the following latest versions:

What do you think?