-
Notifications
You must be signed in to change notification settings - Fork 1.1k
USWDS 3.8.2 #6016
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
USWDS 3.8.2 #6016
Conversation
USWDS - Hotfix: Remove classlist-polyfill dependency
USWDS - Styles: Remove `.scss` extension causing linting issue
mahoneycm
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM!
amyleadem
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looking good to me! I just need to get the .tgz from the draft release to check the final items.
uswds:
- Confirmed all USWDS items tagged as part of 3.8.2 have been merged into the
release.3.8.2branch - Confirmed the hash in the release notes matches the
.txtfile and the .tgz file- The .text and release notes match. Need to confirm in .tgz file.
- Confirmed the contents in the
.tgzare present- Need .tgz file to confirm
- Confirmed no new issues after running
npm audit fix - Install branch on uswds-site and confirm no errors on start or build
- Confirm the README update makes sense and is free from error
Release description:
- Confirmed that changes from the 3.8.2 milestone are included in the release notes
- Confirmed no spelling or grammatical errors
- Confirmed the dependency update table is accurate
- Confirmed listed vulnerabilities are accurate
amyleadem
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Update: I confirmed the tgz hash matches the documented hash. I also confirmed that the contents of the tgz were present.
What's new in USWDS 3.8.2
Dependencies and security
Removed the
classlist-polyfilldependency. This update resolves a Denial of Service (DoS) vulnerability related to theclasslist-polyfilldependency that we do not consider exploitable on the front end of applications. (#6012)Important
This release may affect some functionality in Internet Explorer 11 (IE11). This update removes the polyfill that added full
classListsupport to IE11. USWDS no longer supports IE11, but if your project does, test if this update negatively affects your users and add additional support forclassListif it does.Thanks @aduth for the initial work on removing this dependency.
0vulnerabilities in regular dependencies (dependencies for USWDS projects installed withnpm install @uswds/uswds)5low,11moderate,44high vulnerabilities in devDependencies (development dependencies).Release TGZ SHA-256 hash:
94049e150c2a67dfdb75f140fc664d2e936ef652480a2f88dfdd96922e0a940c