chore: resolve jQuery devDependency CVE #11352
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
Update the internal jQuery version (used for tests) to the latest version to resolve a CVE.
Motivation and Context
This PR resolved a jQuery common vulnerability affecting jQuery < 3.
As Foundation supports jQuery
>=2.2.0
, the jQuery peer dependency is not changed. PeerDependencies versions inpackage.json
should only reflect the actual compatibility with the package, regardless of promotion or "potential" security issue. It's up to the end developer to choose the package version corresponding to its own needs and to the risks comming with its own usage.Types of changes
functionality to change)
Checklist (all required):
develop
orsupport/*
).I have updated the documentation accordingly to my changes (if relevant).I have added tests to cover my changes (if relevant).