-
-
Notifications
You must be signed in to change notification settings - Fork 4.7k
[Security] Bump bootstrap from 3.4.1 to 4.3.1 #14352
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
This is a LOT of changes, not sure we can get that :/ |
|
@skjnldsv Yes its the tooltip only. Bootstrap now also uses https://popper.js.org/ which is the same underlying lib as v-tooltip btw. I pushed some fixes, looks all fine now from a quick test. |
|
We are not affected as we only use tooltip. Maybe a more generalized approach in OCP to show a tooltip would be better anyway. So it is not dependant on what we use in the backend. |
rullzer
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Seems to still work
3fc09f3 to
f35225f
Compare
|
Rebased to fix conflicts |
ChristophWurst
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Tested and still works 👍
|
Seems that arrow function of the tooltip sources are not properly converted, therefore tests fail and IE doesn't work currently. I'll have a look. |
f35225f to
0b3f2c0
Compare
|
Pushed a fix to just use the dist file for tooltip which is also there. Let's see if CI is happier about that. |
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
a3cfb26 to
31fb3d8
Compare
This comment has been minimized.
This comment has been minimized.
Bumps [bootstrap](https://github.com/twbs/bootstrap) from 3.4.1 to 4.3.1. **This update includes security fixes.** - [Release notes](https://github.com/twbs/bootstrap/releases) - [Commits](twbs/bootstrap@v3.4.1...v4.3.1) Signed-off-by: dependabot[bot] <[email protected]>
Signed-off-by: Julius Härtl <[email protected]>
Signed-off-by: Julius Härtl <[email protected]>
Signed-off-by: Julius Härtl <[email protected]>
Signed-off-by: Julius Härtl <[email protected]>
Signed-off-by: Julius Härtl <[email protected]>
Signed-off-by: Julius Härtl <[email protected]>
31fb3d8 to
9e3335f
Compare
|
Pushed another fix, runs fine locally now. Let's see: https://drone.nextcloud.com/nextcloud/server/16843/253 |
|
🤖 beep boop beep 🤖 Here are the logs for the failed build: Status of 16843: failureDB=mysql, ENABLE_REDIS=false, PHP=7.3Show full logTESTS=acceptance, TESTS-ACCEPTANCE=app-files
Show full logTESTS=acceptance, TESTS-ACCEPTANCE=app-files-tags
Show full logTESTS=acceptance, TESTS-ACCEPTANCE=login
Show full log |
ChristophWurst
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🙈 on the DOMParser stuff
👍 on the rest
rullzer
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
CI happy. I'm happy.
Bumps bootstrap from 3.4.1 to 4.3.1. This update includes security fixes.
Vulnerabilities fixed
Sourced from The GitHub Security Advisory Database.
Release notes
Sourced from bootstrap's releases.
Commits
8fa0d30Release v4.3.1. (#28252)dae20daRemove unneeded glob. (#28249)10b97f6Fix npm package contents7bc4d2eAdd sanitize template option for tooltip/popover plugins.bf2515aUpdate RFS to v8.0.1 (#28245)45ced60Update font size (#28232)1ded0d6Release v4.3.0 (#28228)3aa0770docs snippets: a few more minor tweaks (#28225)adf16datoasts.md: Remove uselessdivs.2bfe581Remove stray parameter from capture.Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Note: This repo was added to Dependabot recently, so you'll receive a maximum of 5 PRs for your first few update runs. Once an update run creates fewer than 5 PRs we'll remove that limit.
You can always request more updates by clicking
Bump nowin your Dependabot dashboard.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge@dependabot reopenwill reopen this PR if it is closed@dependabot ignore this [patch|minor|major] versionwill close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)@dependabot use these labelswill set the current labels as the default for future PRs for this repo and language@dependabot use these reviewerswill set the current reviewers as the default for future PRs for this repo and language@dependabot use these assigneeswill set the current assignees as the default for future PRs for this repo and language@dependabot use this milestonewill set the current milestone as the default for future PRs for this repo and language@dependabot badge mewill comment on this PR with code to add a "Dependabot enabled" badge to your readmeAdditionally, you can set the following in your Dependabot dashboard:
Finally, you can contact us by mentioning @dependabot.