Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SPA implementation - Jquery #2874

Closed
laurenb33 opened this issue Jun 26, 2024 · 4 comments
Closed

SPA implementation - Jquery #2874

laurenb33 opened this issue Jun 26, 2024 · 4 comments
Assignees
Labels
waiting waiting on external resources

Comments

@laurenb33
Copy link
Collaborator

laurenb33 commented Jun 26, 2024

Per the Yale's Info Security team, we need to update all of the jquery-rails gem to the most current version of jquery (https://blog.jquery.com/). Our extension to do this is until December 2024. The DCS SPA report is in the our Team channel. See related ticket #2790

There is a ticket for the community of JQuery developers work on a fix to stop supporting versions 1 and 2: rails/jquery-rails#292 @laurenb33 will check this periodically to see if any progress has been made on that front.

@mikeapp
Copy link
Collaborator

mikeapp commented Sep 10, 2024

@jpengst jpengst self-assigned this Sep 19, 2024
@jpengst
Copy link
Collaborator

jpengst commented Sep 19, 2024

I think we're already on the most recent version of jquery-rails (4.6.0)
https://rubygems.org/gems/jquery-rails/versions/4.6.0

@laurenb33
Copy link
Collaborator Author

John replied- he said he's going to have Colby contact me to take a look at the specific risk the Jquery flag poses to the DCS.

@jillpe jillpe added the waiting waiting on external resources label Sep 23, 2024
@laurenb33
Copy link
Collaborator Author

I heard back from Colby - she said:
Since the application is moderate risk and it’s not actually running the older versions (they’re just stored in an assets folder), I think it is appropriate to accept this risk rather than fork the repository. I’ll let my team know to renew the exception.
I think we're ready to close! 🎉🎉🎉🎉

@jillpe jillpe closed this as completed Sep 24, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
waiting waiting on external resources
Projects
None yet
Development

No branches or pull requests

4 participants