Skip to content

Commit e36c0ee

Browse files
fix: update jQuery to 4.0.0 to resolve pen test finding (XSS/Prototype Pollution CVEs)
- Bump jquery from ^3.7.1 to ^4.0.0 - Bump @types/jquery from ^3.5.31 to ^4.0.0 - Sync USWDS SVG assets with node_modules to fix build conflicts
1 parent 6aa0282 commit e36c0ee

5 files changed

Lines changed: 14 additions & 39 deletions

File tree

package.json

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,7 @@
3333
"@angular/router": "~15.2.10",
3434
"@auth0/angular-jwt": "^5.2.0",
3535
"@fullcalendar/core": "^6.1.14",
36-
"@types/jquery": "^3.5.31",
36+
"@types/jquery": "^4.0.0",
3737
"@types/quill": "2.0.14",
3838
"@uswds/uswds": "^3.11.0",
3939
"ag-grid": "^18.1.2",
@@ -53,7 +53,7 @@
5353
"file-saver": "^2.0.5",
5454
"font-awesome": "^4.7.0",
5555
"http-proxy-middleware": "2.0.7",
56-
"jquery": "^3.7.1",
56+
"jquery": "^4.0.0",
5757
"json2csv": "^6.0.0-alpha.2",
5858
"mammoth": "^1.8.0",
5959
"moment": "^2.30.1",
@@ -109,4 +109,4 @@
109109
"webpack-dev-server": "^4.15.0",
110110
"yarn-audit-fix": "^9.3.10"
111111
}
112-
}
112+
}
Lines changed: 1 addition & 10 deletions
Loading
Lines changed: 1 addition & 10 deletions
Loading

src/assets/uswds/img/loader.svg

Lines changed: 1 addition & 1 deletion
Loading

yarn.lock

Lines changed: 8 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -2056,12 +2056,10 @@
20562056
resolved "https://registry.yarnpkg.com/@types/jasmine/-/jasmine-4.3.2.tgz#27045b95e1249e67ef02c7966e12003fb25df18b"
20572057
integrity sha512-lKkWBcbxEZX/7nxPqEtv/OjPLaBa2j0o+hmv5Yn83b/+11C1kfBAkgvmrb13WDkmizUJ3B+jYrWh4M0YRtrzEQ==
20582058

2059-
"@types/jquery@^3.5.31":
2060-
version "3.5.32"
2061-
resolved "https://registry.yarnpkg.com/@types/jquery/-/jquery-3.5.32.tgz#3eb0da20611b92c7c49ebed6163b52a4fdc57def"
2062-
integrity sha512-b9Xbf4CkMqS02YH8zACqN1xzdxc3cO735Qe5AbSUFmyOiaWAbcpqh9Wna+Uk0vgACvoQHpWDg2rGdHkYPLmCiQ==
2063-
dependencies:
2064-
"@types/sizzle" "*"
2059+
"@types/jquery@^4.0.0":
2060+
version "4.0.0"
2061+
resolved "https://registry.yarnpkg.com/@types/jquery/-/jquery-4.0.0.tgz#b7717b6e5103b50b115b707950357f302cc92fba"
2062+
integrity sha512-Z+to+A2VkaHq1DfI2oSwsoCdhCHMpTSgjWzNcbNlRGYzksDBpPUgEcAL+RQjOBJRaLoEAOHXxqDGBVP+BblBwg==
20652063

20662064
"@types/json-schema@*", "@types/json-schema@^7.0.8", "@types/json-schema@^7.0.9":
20672065
version "7.0.15"
@@ -2185,11 +2183,6 @@
21852183
"@types/node" "*"
21862184
"@types/send" "*"
21872185

2188-
"@types/sizzle@*":
2189-
version "2.3.9"
2190-
resolved "https://registry.yarnpkg.com/@types/sizzle/-/sizzle-2.3.9.tgz#d4597dbd4618264c414d7429363e3f50acb66ea2"
2191-
integrity sha512-xzLEyKB50yqCUPUJkIsrVvoWNfFUbIZI+RspLWt8u+tIW/BetMBZtgV2LY/2o+tYH8dRvQ+eoPf3NdhQCcLE2w==
2192-
21932186
"@types/sockjs@^0.3.33":
21942187
version "0.3.36"
21952188
resolved "https://registry.yarnpkg.com/@types/sockjs/-/sockjs-0.3.36.tgz#ce322cf07bcc119d4cbf7f88954f3a3bd0f67535"
@@ -6147,10 +6140,10 @@ jest-worker@^27.4.5:
61476140
merge-stream "^2.0.0"
61486141
supports-color "^8.0.0"
61496142

6150-
jquery@^3.7.1:
6151-
version "3.7.1"
6152-
resolved "https://registry.yarnpkg.com/jquery/-/jquery-3.7.1.tgz#083ef98927c9a6a74d05a6af02806566d16274de"
6153-
integrity sha512-m4avr8yL8kmFN8psrbFFFmB/If14iN5o9nw/NgnnM+kybDJpRsAynV2BsfpTYrTRysYUdADVD7CkUUizgkpLfg==
6143+
jquery@^4.0.0:
6144+
version "4.0.0"
6145+
resolved "https://registry.yarnpkg.com/jquery/-/jquery-4.0.0.tgz#95c33ac29005ff72ec444c5ba1cf457e61404fbb"
6146+
integrity sha512-TXCHVR3Lb6TZdtw1l3RTLf8RBWVGexdxL6AC8/e0xZKEpBflBsjh9/8LXw+dkNFuOyW9B7iB3O1sP7hS0Kiacg==
61546147

61556148
js-tokens@^4.0.0:
61566149
version "4.0.0"

0 commit comments

Comments
 (0)