Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix #10429 jquery dependency needs to be updated to 3.5.0 or newer #10684

Closed
wants to merge 1 commit into from

Conversation

breser
Copy link
Member

@breser breser commented Sep 2, 2020

There is a vulnerability in the version currently being used.
GHSA-gxr4-xjj5-5px2

closes: #10429


^ Add meaningful description above

Read the Pull Request Guidelines for more information.
In case of fundamental code change, Airflow Improvement Proposal (AIP) is needed.
In case of a new dependency, check compliance with the ASF 3rd Party License Policy.
In case of backwards incompatible changes please leave a note in UPDATING.md.

There is a vulnerability in the version currently being used.
GHSA-gxr4-xjj5-5px2
@boring-cyborg boring-cyborg bot added the area:webserver Webserver related Issues label Sep 2, 2020
@boring-cyborg
Copy link

boring-cyborg bot commented Sep 2, 2020

Congratulations on your first Pull Request and welcome to the Apache Airflow community! If you have any issues or are unsure about any anything please check our Contribution Guide (https://github.com/apache/airflow/blob/master/CONTRIBUTING.rst)
Here are some useful points:

  • Pay attention to the quality of your code (flake8, pylint and type annotations). Our pre-commits will help you with that.
  • In case of a new feature add useful documentation (in docstrings or in docs/ directory). Adding a new operator? Check this short guide Consider adding an example DAG that shows how users should use it.
  • Consider using Breeze environment for testing locally, it’s a heavy docker but it ships with a working Airflow and a lot of integrations.
  • Be patient and persistent. It might take some time to get a review or get the final approval from Committers.
  • Please follow ASF Code of Conduct for all communication including (but not limited to) comments on Pull Requests, Mailing list and Slack.
  • Be sure to read the Airflow Coding style.
    Apache Airflow is a community-driven project and together we are making it better 🚀.
    In case of doubts contact the developers at:
    Mailing List: [email protected]
    Slack: https://apache-airflow-slack.herokuapp.com/

@ryw
Copy link
Member

ryw commented Sep 2, 2020

@ryanahamilton can you review/test this?

@ryanahamilton
Copy link
Contributor

@breser can you include your modified airflow/www/yarn.lock in this PR please?

@kaxil
Copy link
Member

kaxil commented Sep 3, 2020

jQuery 3.5.0 does not work well with FAB, past issue: #8599

@breser
Copy link
Member Author

breser commented Sep 3, 2020

I'm closing this then because I have no time/ability to fix these deeper issues.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area:webserver Webserver related Issues
Projects
None yet
Development

Successfully merging this pull request may close these issues.

jquery dependency needs to be updated to 3.5.0 or newer
4 participants