Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Review Tiqr jquery + bootstrap setup #305

Open
phavekes opened this issue Dec 1, 2024 · 1 comment
Open

Review Tiqr jquery + bootstrap setup #305

phavekes opened this issue Dec 1, 2024 · 1 comment

Comments

@phavekes
Copy link
Member

phavekes commented Dec 1, 2024

This issue is imported from pivotal - Originaly created at Oct 26, 2020 by Michiel Kodde

Jquery and Bootstrap resources are tracked in the webfolder of tiqr. This is potentially harmfull as the security scanners are not able to test these dependencies for known vulnerabilities. For example. The selected version of JQuery has 4 known vulnerabilities

https://snyk.io/test/npm/jquery/1.11.3

These packages should be tracked using yarn.

@phavekes phavekes self-assigned this Dec 1, 2024
@phavekes phavekes removed their assignment Dec 1, 2024
@johanib
Copy link
Contributor

johanib commented Jan 15, 2025

I dont think this dep is still used.

It needs to be removed from the stepup-bundle, then it will be gone here.
https://github.com/OpenConext/Stepup-bundle/blob/6.0.17/src/Resources/public/js/jquery-1.11.2.min.js

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Status: New
Development

No branches or pull requests

2 participants