Skip to content

Conversation

@reedloden
Copy link
Contributor

Update grunt-contrib-uglify dependency to v0.9.2 in order to fix a security issue fixed in uglify-js v2.4.24.

mishoo/UglifyJS#751
https://zyan.scripts.mit.edu/blog/backdooring-js/

Update grunt-contrib-uglify dependency to v0.9.2 in order to
fix security issue fixed in uglify-js v2.4.24.

mishoo/UglifyJS#751
https://zyan.scripts.mit.edu/blog/backdooring-js/
@reedloden reedloden force-pushed the bump-grunt-contrib-uglify branch from 7b1ae0c to 63c32d3 Compare August 24, 2015 19:25
@mgol
Copy link
Member

mgol commented Aug 24, 2015

LGTM

@mgol mgol self-assigned this Aug 24, 2015
@mgol mgol added this to the 3.0.0 milestone Aug 24, 2015
@mgol
Copy link
Member

mgol commented Aug 26, 2015

Note, thought, that for jQuery this is not a security update. All releases are done using jquery-release which clones the proper repository and invokes npm install on it. This means the currently used grunt-contrib-uglify version will install uglify-js 2.4.24 i.e. the one with the fix.

@mgol mgol closed this in 835e921 Sep 7, 2015
mgol pushed a commit that referenced this pull request Sep 7, 2015
Update grunt-contrib-uglify dependency to v0.9.2 in order to
avoid a security issue fixed in uglify-js v2.4.24.

mishoo/UglifyJS#751
https://zyan.scripts.mit.edu/blog/backdooring-js/

(cherry-picked from 835e921)

Closes gh-2556
@mgol mgol removed their assignment Sep 7, 2015
@lock lock bot locked as resolved and limited conversation to collaborators Jan 19, 2019
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants