Cleanup of Bootstrap XSS Security issue#18
Open
code-for-coffee wants to merge 2 commits intoDesignRevision:masterfrom
Open
Cleanup of Bootstrap XSS Security issue#18code-for-coffee wants to merge 2 commits intoDesignRevision:masterfrom
code-for-coffee wants to merge 2 commits intoDesignRevision:masterfrom
Conversation
SharonMeeus
approved these changes
Jan 14, 2020
|
This merge would really be appreciated. Having to manually patch on the developer's end is quiet cumbersome. |
|
Can we please get this merged? |
|
Is this going to be merged anytime soon? |
|
would really appreciate this merge. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
#17 pointed out that some security dependencies are out of date (and was originally an attempt at fixing the Bootstrap XSS issue - https://www.npmjs.com/advisories/891).
This MR is an attempt to clean up some of them.
shards-ui@3.0.0resolves the bootstrap problem as does this package.json itself now.I was curious if there is a good way to test this since there is no contribution.md file in the repository? Thank you so much!