svg-GHC-2 / frank

0 stars 0 forks source link

Update dependency bootstrap to v4.3.1 #27

Closed mend-for-github-com[bot] closed 1 year ago

mend-for-github-com[bot] commented 1 year ago

This PR contains the following updates:

Package Type Update Change
bootstrap (source) dependencies minor 4.1.0 -> 4.3.1

By merging this PR, the issue #4 will be automatically resolved and closed:

Severity CVSS Score CVE
Medium Medium 6.1 CVE-2018-14040
Medium Medium 6.1 CVE-2018-14041
Medium Medium 6.1 CVE-2018-14042
Medium Medium 6.1 CVE-2019-8331

Release Notes

twbs/bootstrap ### [`v4.3.1`](https://togithub.com/twbs/bootstrap/releases/tag/v4.3.1) [Compare Source](https://togithub.com/twbs/bootstrap/compare/v4.3.0...v4.3.1) - **Security:** Fixed an XSS vulnerability (CVE-2019-8331) in our tooltip and popover plugins by implementing a new HTML sanitizer - Fixed a small issue with our RFS (responsive font sizes) mixins ### [`v4.3.0`](https://togithub.com/twbs/bootstrap/releases/tag/v4.3.0) [Compare Source](https://togithub.com/twbs/bootstrap/compare/v4.2.1...v4.3.0) ##### Highlights - **New:** Added `.stretched-link` utility to make any anchor the size of it's nearest `position: relative` parent, perfect for entirely clickable cards! - **New:** Added `.text-break` utility for applying `word-break: break-word` - **New:** Added `.rounded-sm` and `.rounded-lg` for small and large `border-radius`. - **New:** Added `.modal-dialog-scrollable` modifier class for scrolling content *within* a modal. - **New:** Added responsive `.list-group-horizontal` modifier classes for displaying list groups as a horizontal row. - **Improved:** Reduced our compiled CSS by using `null` for variables that by default inherit their values from other elements (e.g., `$headings-color` was `inherit` and is now `null` until you modifier it in your custom CSS). - **Improved:** Badge focus styles now match their `background-color` like our buttons. - **Fixed:** Silenced bad selectors in our JS plugins for the `href` HTML attribute to avoid JavaScript errors. Please try to use [valid selectors](https://www.w3.org/TR/CSS21/syndata.html#value-def-identifier) or the `data-target` HTML attribute/`target` option where available. - **Fixed:** Reverted v4.2.1's change to the breakpoint and grid container Sass maps that blocked folks from upgrading when modifying those default variables. - **Fixed:** Restored `white-space: nowrap` to `.dropdown-toggle` (before v4.2.1 it was on all `.btn`s) so carets don't wrap to new lines. - **Deprecated:** `img-retina`, `invisible`, `float`, and `size` mixins are now deprecated and will be removed in v5. ##### Links - [Read the full ship list](https://togithub.com/twbs/bootstrap/issues/27893) - [Review the project board](https://togithub.com/twbs/bootstrap/projects/16) ### [`v4.2.1`](https://togithub.com/twbs/bootstrap/releases/tag/v4.2.1) [Compare Source](https://togithub.com/twbs/bootstrap/compare/v4.1.3...v4.2.1) Bump to v4.2.1 to republish package on npm. [See v4.2.0 release notes](https://togithub.com/twbs/bootstrap/releases/tag/v4.2.0) for changes introduced in v4.2. ### [`v4.1.3`](https://togithub.com/twbs/bootstrap/releases/tag/v4.1.3) [Compare Source](https://togithub.com/twbs/bootstrap/compare/v4.1.2...v4.1.3) - **Fixed:** Removed the `:not(:root)` selector from our `svg` Reboot styles, resolving an issue that caused all inline SVGs ignore `vertical-align` styles via single class due to higher specificity. - **Fixed:** Moved the browserslist config from our `package.json` to a separate file to avoid unintended inherited browser settings across npm projects. - **Fixed:** Buttons in custom file inputs are once again clickable when focused. - **Improved:** Bootstrap's plugins can now be imported separately in any contexts because they are now UMD ready. - **Improved:** `.form-control`s now have a fixed `height` to compensate for differences in computed height across different `type`s. This also fixes some IE alignment issues. - **Improved:** Added `Noto Color Emoji` to our system font stack for better rendering in Linux OSes. ### [`v4.1.2`](https://togithub.com/twbs/bootstrap/releases/tag/v4.1.2) [Compare Source](https://togithub.com/twbs/bootstrap/compare/v4.1.1...v4.1.2) - Fixed an XSS vulnerability in tooltip, collapse, and scrollspy plugins - Improved how we query elements in our JavaScript plugins - Inline SVGs now have the same vertical alignment as images - Fixed issues with double transitions on carousels - Added Edge and IE10-11 fallbacks to our floating labels example - Various improvements to form controls, including disabled states on file inputs and unified focus styles for selects Checkout the [v4.1.2 ship list](https://togithub.com/twbs/bootstrap/issues/26423) and [GitHub project](https://togithub.com/twbs/bootstrap/projects/14) for the full details. ### [`v4.1.1`](https://togithub.com/twbs/bootstrap/releases/tag/v4.1.1) [Compare Source](https://togithub.com/twbs/bootstrap/compare/v4.1.0...v4.1.1) **Our first patch release for Bootstrap 4!** Here's a quick rundown of some of the changes: - Added validation styles for file inputs - Improved printing of dark tables - Suppressed that `text-hide` deprecation notice by default - Cleaned up some JS globals and improve coverage - Bumped dependencies, namely Jekyll - Fixed docs issue with incorrect name for our monospace font utility Checkout the [v4.1.1 ship list](https://togithub.com/twbs/bootstrap/issues/25971) and [GitHub project](https://togithub.com/twbs/bootstrap/projects/13) for the full details.