Update dependency bootstrap to v5 [SECURITY] #2
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "renovate/npm-bootstrap-vulnerability"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
^4.6.2
->^5.0.0
Bootstrap Cross-Site Scripting (XSS) vulnerability
CVE-2024-6531 / GHSA-vc8w-jr9v-vj7f
More information
Details
A vulnerability has been identified in Bootstrap that exposes users to Cross-Site Scripting (XSS) attacks. The issue is present in the carousel component, where the data-slide and data-slide-to attributes can be exploited through the href attribute of an tag due to inadequate sanitization. This vulnerability could potentially enable attackers to execute arbitrary JavaScript within the victim's browser.
Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L
References
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Release Notes
twbs/bootstrap (bootstrap)
v5.0.0
Compare Source
Highlights
#32155: Updated
make-col()
mixin to generate equal columns when no size is specified#32763: Added new
color-scheme()
mixin#33389: Dropdown menus now have option become clickable
#33453: Added new docs footer
#33548: Offcanvas header components are now vertically aligned
#33549: Added offcanvas-top modifier
#33634: Added support for
.dropdown-item
s wrapped in<li>
s#33626: Fix v5 regressions in tab dropdown functionality
🚀 Features
color-scheme
mixin🎨 CSS
color-scheme
mixin.nav-link
color consistent when using buttons:read-only
css selector instead[readonly]
for consistencyborder-top
on Firefox☕️ JavaScript
hide
method of dropdownisDisabled
util on dropdownnoop
functionselectMenuItem
method private.dropdown-item
wrapped in<li>
tagsaltBoundary
option📖 Docs
rel=noopener
attributeboundary
optionboundary
optionboundary
option descriptionExamples
🌎 Accessibility
🏭 Tests
data-bs-backdrop="static"
from modal tests🧰 Misc
📦 Dependencies
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.
690865c280
to862c664ca4
862c664ca4
tob6e1220a7a
b6e1220a7a
to5d615256c8
5d615256c8
to53aac0c662
53aac0c662
to66f5ac3df3
66f5ac3df3
tod280fbfee3
d280fbfee3
to787f267e14
787f267e14
tob34f769055
b34f769055
to93f915da06
93f915da06
tod8581db2de
d8581db2de
to31c07ac276
31c07ac276
todfa804cd7c
dfa804cd7c
toffa103dee7
ffa103dee7
tof8d2ea90f4
Major update, not possible without frontend-rewrite.
f8d2ea90f4
toc7aaf6accd
c7aaf6accd
to9d062f28c7
9d062f28c7
tod657ab13ac
d657ab13ac
todcaa2bdb36
dcaa2bdb36
tod5f5f4e83e
d5f5f4e83e
to9e3c5daef5
Renovate Ignore Notification
Because you closed this PR without merging, Renovate will ignore this update. You will not get PRs for any future
5.x
releases. But if you manually upgrade to5.x
then Renovate will re-enableminor
andpatch
updates automatically.If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR.
Pull request closed