Details
-
Bug
-
Resolution: Fixed
-
High
-
4.6.0, 3.3.36, 4.5.4
-
None
Description
Pagebuilder specifies a very old 3.3.1 jQuery in yarn. This old version is not actually installed, but we should remove or upgrade it anyway.
https://github.com/ibexa/page-builder/blob/4.5/src/bundle/ui-dev/package.json#L7
In admin-ui-assets/package.json we specify minimum 3.5.1, so it seems 3.3.1 will never be installed. In public/bundles/ibexaadminuiassets/ we even specify minimum 3.7.0 and include 3.7.1. We should bump the requirement anyway to avoid triggering false positives in security scanners.
v3: https://github.com/ezsystems/ezplatform-page-builder/pull/988 (merged)
In v4, jQuery is not even used and can be removed.
v4 test: https://github.com/ibexa/page-builder/pull/328 (closed)
v4 merge up: https://github.com/ibexa/page-builder/pull/331 (merged)