Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update to latest bootstrap release (or use another framework) #104

Closed
fgrehm opened this issue Feb 18, 2020 · 4 comments
Closed

Update to latest bootstrap release (or use another framework) #104

fgrehm opened this issue Feb 18, 2020 · 4 comments

Comments

@fgrehm
Copy link
Owner

fgrehm commented Feb 18, 2020

Project is using a really old release of bootstrap (2.2.2), I think we should update to the latest release available or use another lightweight framework.

The project's UI is super simple that we could even just get away with a reset framework + a handful of styles.

cc @pseudomuto in case you have any thoughts (also sorry for the @ spam today, I'm using the gem on a few side projects now)

@fgrehm
Copy link
Owner Author

fgrehm commented Feb 18, 2020

While we are here, we might also drop jquery and simplify our JS too (or at least switch over to zepto)

@pseudomuto
Copy link
Contributor

I'd be down for simplifying the UI stuff. There was a PR a while back to remove the dependency on the asset pipeline, seems like this would be another step in the right direction.

I'm pretty swamped for the next week, but happy to review a PR or two, or jump on it myself after

@pda
Copy link

pda commented Oct 19, 2020

we might also drop jquery and simplify our JS too

FYI this came up in an internal security assessment / pentest of an application that included letter_opener_web:

Dynamic testing of the Buildkite application revealed that it is using version 1.8.3 of the jQuery library. This version of jQuery has known security issues that, in some circumstances, can introduce cross-site scripting (XSS) vulnerabilities

@fgrehm
Copy link
Owner Author

fgrehm commented Oct 20, 2021

This is finally hapenning, see #113

@fgrehm fgrehm closed this as completed Oct 20, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants