Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

What is the plan for the Google Play vulnerability with JQuery? #1032

Open
gsgaine opened this issue Dec 1, 2019 · 1 comment
Open

What is the plan for the Google Play vulnerability with JQuery? #1032

gsgaine opened this issue Dec 1, 2019 · 1 comment

Comments

@gsgaine
Copy link

gsgaine commented Dec 1, 2019

Hello folks,

We are rounding a 'bout where our SDK is under scrutiny from Google Play.
What is our plan to upgrade our SDK to utilize underlying JQuery-3.4.0.min.js
My drupalgap iOS and Android app seems to break when using versions greater than JQuery 1.11.1.min.js

RE: https://snyk.io/blog/after-three-years-of-silence-a-new-jquery-prototype-pollution-vulnerability-emerges-once-again/

Well, there, I said it.

@signalpoint
Copy link
Owner

What is our plan to upgrade our SDK to utilize underlying JQuery-3.4.0.min.js

I am no longer able to support DrupalGap 7 (which is built on top of jQuery). I'd welcome any code contributions that would like to address the situation.

Otherwise, I am able to support DrupalGap 8 (which is built with vanilla js) and it works for both Drupal 8 and Drupal 7.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants