Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove Bootstrap version reference from tooltip.scss #35485

Merged
merged 1 commit into from
Nov 29, 2022

Conversation

AlvaroBrey
Copy link
Member

@AlvaroBrey AlvaroBrey commented Nov 29, 2022

We've had some reports that Nextcloud is using an outdated/deprecated Bootstrap version v3.3.5.

I believe this to be caused by the string "Bootstrap v3.3.5" removed in this PR, which after bundling ends up in core-common.js, and trips up some security scanners.

It may also be worth investigating why the comments are not getting stripped when bundling the JS.

cc @nickvergessen

@AlvaroBrey AlvaroBrey added the 3. to review Waiting for reviews label Nov 29, 2022
@AlvaroBrey AlvaroBrey self-assigned this Nov 29, 2022
@szaimen szaimen added this to the Nextcloud 26 milestone Nov 29, 2022
@szaimen szaimen requested review from come-nc, a team, PVince81, artonge and skjnldsv and removed request for a team November 29, 2022 11:56
@skjnldsv
Copy link
Member

It's the little things 😅

@szaimen
Copy link
Contributor

szaimen commented Nov 29, 2022

/compile amend /

@szaimen szaimen added 4. to release Ready to be released and/or waiting for tests to finish and removed 3. to review Waiting for reviews labels Nov 29, 2022
We've had some reports that Nextcloud is using an outdated/deprecated Bootstrap version v3.3.5.

I believe this to be caused by the string "Bootstrap v3.3.5" in the changed line, which after bundling ends up in `core-common.js`, and trips up some security scanners.

It may also be worth investigating why the comments are not getting stripped when bundling the JS.

Signed-off-by: Álvaro Brey <alvaro.brv@gmail.com>
Signed-off-by: nextcloud-command <nextcloud-command@users.noreply.github.com>
@nextcloud-command nextcloud-command force-pushed the chore/remove-bootstrap-version-comment branch from 78de638 to 79c3970 Compare November 29, 2022 14:21
@szaimen szaimen merged commit 366a0dc into master Nov 29, 2022
@szaimen szaimen deleted the chore/remove-bootstrap-version-comment branch November 29, 2022 15:32
@welcome
Copy link

welcome bot commented Nov 29, 2022

Thanks for your first pull request and welcome to the community! Feel free to keep them coming! If you are looking for issues to tackle then have a look at this selection: https://github.com/nextcloud/server/issues?q=is%3Aopen+is%3Aissue+label%3A%22good+first+issue%22

@nickvergessen
Copy link
Member

/backport to stable25

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
4. to release Ready to be released and/or waiting for tests to finish
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants