Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency bootstrap to v3.4.1 #9

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

mend-for-github-com[bot]
Copy link

@mend-for-github-com mend-for-github-com bot commented Feb 29, 2024

This PR contains the following updates:

Package Type Update Change
bootstrap (source) dependencies minor 3.3.6 -> 3.4.1

By merging this PR, the issue #3 will be automatically resolved and closed:

Severity CVSS Score CVE Reachability
Medium Medium 6.1 CVE-2016-10735
Medium Medium 6.1 CVE-2018-14042
Medium Medium 6.1 CVE-2018-20676
Medium Medium 6.1 CVE-2018-20677
Medium Medium 6.1 CVE-2019-8331

Release Notes

twbs/bootstrap (bootstrap)

v3.4.1

Compare Source

  • Security: Fixed an XSS vulnerability (CVE-2019-8331) in our tooltip and popover plugins by implementing a new HTML sanitizer
  • Handle bad selectors (#) in data-target for Dropdowns
  • Clarified tooltip selector documentation
  • Added support for NuGet contentFiles

v3.4.0

Compare Source

  • New: Added a .row-no-gutters class.
  • New: Added docs searching via Algolia.
  • Fixed: Resolved an XSS issue in Alert, Carousel, Collapse, Dropdown, Modal, and Tab components. See https://snyk.io/vuln/npm:bootstrap:20160627 for details.
  • Fixed: Added padding to .navbar-fixed-* on modal open
  • Fixed: Removed the double border on <abbr> elements.
  • Removed Gist creation in web-based Customizer since anonymous gists were disabled long ago by GitHub.
  • Removed drag and drop support from Customizer since it didn't work anymore.
  • Added a dropdown to the docs nav for newer and previous versions.
  • Update the docs to use a new baseurl, /docs/3.4/, to version the v3.x documentation like we do with v4.
  • Reorganized the v3 docs CSS to use Less.
  • Switched to BrowserStack for tests.
  • Updated links to always use https and fix broken URLs.
  • Replaced ZeroClipboard with clipboard.js

v3.3.7

Compare Source

Release announcement blog post: https://blog.getbootstrap.com/2016/07/25/bootstrap-3-3-7-released/

JavaScript
  • #​19192 Fix keyboard navigation for toggle buttons (checkbox, radio, single toggle) following a mouse click
  • #​19659: Clear tooltip's $element to prevent leaking memory
  • #​20019: Avoid calling jQuery('#') since it's a syntax error in jQuery 3
  • #​20259: Backport jQuery-related JS unit test fixes from v4
  • #​20278: button.js: Set disabled property in addition to disabled attribute, for jQuery 3 compatibility
  • #​20313: Avoid using $.offset() on SVGs since it gives incorrect results in jQuery 3
  • #​20338: Update jQuery version check and jQuery dependency version range to allow jQuery 3
CSS

No significant changes.

Accessibility
  • #​19704: Add aria-label and callout about labeling pagination components
Docs
  • #​19263 Bump html5shiv to v3.7.3
  • #​19273 Port v4 browser support table format to v3
  • #​19893: Update jQuery to v1.12.4
  • Numerous Wall of Browser Bugs updates

  • If you want to rebase/retry this PR, check this box

@mend-for-github-com mend-for-github-com bot added the security fix Security fix generated by Mend label Feb 29, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security fix Security fix generated by Mend
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants