Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(deps): update dependency bootstrap to v4.1.2 [security] #81

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link

@renovate renovate bot commented Dec 5, 2019

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
bootstrap (source) 4.0.0 -> 4.1.2 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2018-14041

In Bootstrap 4.x before 4.1.2, XSS is possible in the data-target property of scrollspy. This is similar to CVE-2018-14042.


Release Notes

twbs/bootstrap (bootstrap)

v4.1.2

Compare Source

  • Fixed an XSS vulnerability in tooltip, collapse, and scrollspy plugins
  • Improved how we query elements in our JavaScript plugins
  • Inline SVGs now have the same vertical alignment as images
  • Fixed issues with double transitions on carousels
  • Added Edge and IE10-11 fallbacks to our floating labels example
  • Various improvements to form controls, including disabled states on file inputs and unified focus styles for selects

Checkout the v4.1.2 ship list and GitHub project for the full details.

v4.1.1

Compare Source

Our first patch release for Bootstrap 4! Here's a quick rundown of some of the changes:

  • Added validation styles for file inputs
  • Improved printing of dark tables
  • Suppressed that text-hide deprecation notice by default
  • Cleaned up some JS globals and improve coverage
  • Bumped dependencies, namely Jekyll
  • Fixed docs issue with incorrect name for our monospace font utility

Checkout the v4.1.1 ship list and GitHub project for the full details.

v4.1.0

Compare Source

  • Added new custom range form control.
  • Added new .carousel-fade modifier to switch carousel from horizontal sliding to crossfade.
  • Added new .dropdown-item-text for plaintext dropdown items.
  • Added new .flex-fill, .flex-grow-*, and .flex-shrink-* utilities.
  • Added new .table-borderless variant for tables.
  • Added new .text-monospace utility.
  • Added new .text-body (default body color), .text-black-50 (50% opacity black), and .text-white-50 (50% opacity white) utilities.
  • Added new .shadow-* utilities for quickly adding box-shadows.
  • Added ability to disable Popper's positioning in dropdowns.
  • Fixed longstanding issue with Chrome incorrectly rendering cards across CSS columns.
  • Deprecated .text-hide—you'll see a warning during compilation—as it's a dated and undocumented feature.
  • Fixed up Dashboard and Offcanvas examples across Firefox and IE.
  • Breadcrumbs can now use non-string values as dividers.
  • Updated our Theming docs to confirm you cannot use CSS variables in media queries (sorry folks!).

Be sure to look at the ship list and project board for more details on all our fixes.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot force-pushed the renovate/npm-bootstrap-vulnerability branch from 076af67 to 704f0da Compare May 15, 2020 16:55
@renovate renovate bot force-pushed the renovate/npm-bootstrap-vulnerability branch from 704f0da to 270ecc8 Compare July 1, 2020 11:51
@renovate renovate bot force-pushed the renovate/npm-bootstrap-vulnerability branch from 270ecc8 to a6420c1 Compare August 27, 2020 03:59
@renovate renovate bot force-pushed the renovate/npm-bootstrap-vulnerability branch from a6420c1 to 2090fd8 Compare October 28, 2020 22:58
@renovate renovate bot force-pushed the renovate/npm-bootstrap-vulnerability branch from 2090fd8 to e49caa5 Compare January 22, 2021 09:59
@renovate renovate bot force-pushed the renovate/npm-bootstrap-vulnerability branch from e49caa5 to 46cf654 Compare March 7, 2022 10:28
@renovate renovate bot force-pushed the renovate/npm-bootstrap-vulnerability branch from 46cf654 to dfd7b23 Compare September 25, 2022 18:36
@renovate renovate bot force-pushed the renovate/npm-bootstrap-vulnerability branch from dfd7b23 to 5e71b83 Compare March 24, 2023 23:05
@renovate renovate bot changed the title fix(deps): update dependency bootstrap to v4.3.1 [security] fix(deps): update dependency bootstrap to v4.3.1 [security] - autoclosed Oct 25, 2023
@renovate renovate bot closed this Oct 25, 2023
@renovate renovate bot deleted the renovate/npm-bootstrap-vulnerability branch October 25, 2023 20:11
@renovate renovate bot changed the title fix(deps): update dependency bootstrap to v4.3.1 [security] - autoclosed fix(deps): update dependency bootstrap to v4.3.1 [security] Oct 25, 2023
@renovate renovate bot reopened this Oct 25, 2023
@renovate renovate bot restored the renovate/npm-bootstrap-vulnerability branch October 25, 2023 21:27
@renovate renovate bot force-pushed the renovate/npm-bootstrap-vulnerability branch from 5e71b83 to 5c00672 Compare October 25, 2023 21:27
@renovate renovate bot changed the title fix(deps): update dependency bootstrap to v4.3.1 [security] fix(deps): update dependency bootstrap to v4.1.2 [security] Aug 6, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant