swiss / styleguide

admin.ch styleguide
https://swiss.github.io/styleguide
MIT License
123 stars 37 forks source link

Update Library uglify-js, High Vulnerability #602

Closed bit-pro-iew-eui closed 6 years ago

bit-pro-iew-eui commented 6 years ago

image

Update to version >2.6.0

gillerr commented 6 years ago

The project is minified using the latest uglify-js version, i.e. v3.2.0.

uglify-js version 2.4.24 is a dependency of grunt-contrib-uglify v.0.2.7 (latest version is v3.2.1) which itself is a dependency of bootstrap-accessibility-plugin v1.0.2. bootstrap-accessibility-plugin is a fork, made by Liip, of a fork, made by Antistatique, of the original plug-in. There has been next to no development on either forks of this plug-in for more than 2 years. Also note that this plug-in only apply to Bootstrap version 3 and is irrelevant for Bootstrap 4, so it's not likely that anything will done on this plug-in.

Either Liip has to update their fork of bootstrap-accessibility-plugin to use a more recent version of grunt-contrib-uglify plug-in or we can fork the plug-in to update the dependency ourselves.

bit-pro-iew-eui commented 6 years ago

Please @gillerr add a list of the affected components, in order to test them

gillerr commented 6 years ago
bit-pro-iew-eui commented 6 years ago

Ok, no problem detected