-
-
Notifications
You must be signed in to change notification settings - Fork 78.9k
New issue
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
v3.4 release #25679
Comments
I'd like folks to weigh in here for anything else urgent for a v3.x release. We have the v3.4.0-dev branch that was cut awhile ago with a few more changes. I have this snippet from an old blog post draft summarizing some of the changes I was planning for that release:
I might need to roll back system fonts from that (older browsers and OSes had issues with it I think), but dunno about everything else yet. Getting docsearch in there would be hella rad, too. |
My 2 cents:
In my case, that would enable us to switch from a private v3.3.8 fork with the XSS patch applied to the official package. |
what is the timeline for v.3.4 release? |
Would also like to know, the XSS issue needs to be fixed, upgrading to 4.x isn't always a viable option. |
@Thorry84 there is a release branch for 3.4 |
@innabauman I can only see a 3.3.7 tag or a 3.4-dev branch. Did it release branch get pulled? |
there is a PR #26212 |
Shipping an old release is a rather tedious and manual process. I'll try to block out some time to get this out the door soon. |
Any updates when a new version of v3.x will be released with the fix of XSS vulnerability? |
A fix for this known vulnerability and a date to expect the release would be appreciated. |
Any updates @mdo ? When will the fix of XSS vulnerability be released? |
Hi @distinctgrey , How we will able to apply XSS patch to Bootstrap 3.3.7? Thanks in advance, |
Any updates @mdo ? When will the fix of XSS vulnerability be released? |
This comment has been minimized.
This comment has been minimized.
We need urgent help regarding Bootstrap, I am from johnson and johnson team, we are using Bootstrap 3.3.6 for our project, our project is very big, but since it 3.3.6 has security issue so security team does not allow us for releasing, but upgrade to 4.0 is a big task, do have have any idea if we have any alternative way |
Hi Ayan, |
Hi Inna, Thank you for your reply. Can you help us how we will include a fix from 3.4 branch? Thanks in advance. |
Hi @490386Ayan - you can replace your Bootstrap minified JS with this one: Also you mentioned before you were using Bootstrap 3.3.6 - this version is incompatible with jQuery 3. If you were using Bootstrap 3.3.6 with jQuery 1.x then you would be exposed to other potential security issues. If you're upgrading to avoid security issues then you should also upgrade to jQuery 3.3.1. |
Sure, give me your email address and I’ll contact you. We also upgraded jquery for the same reason |
This comment has been minimized.
This comment has been minimized.
Thank you very much. Did Bootstrap3.4 shared by you compatible with Jquery 3 and above? |
Bootstrap 3.3.7 was released in July 2016 and that release added support for jQuery 3 (and fixes a few other issues) |
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
@XhmikosR Is the release globally available? |
The PR isn't merged yet, we'll get to it hopefully soon. I'm still making a few more tweaks. |
@XhmikosR any tentative date when it would be available on "npm"? |
No, sorry. It depends on a few other things. |
Where is the 3.4 branch, I can no longer find it? |
@khadzic according to this #20184 (comment) it's in the master branch. |
@XhmikosR any idea when we might have the 3.4 release available via Package Manager using VS. Thanks |
It doesn't depend purely on me. So please, guys, I understand your position, trust me, that is why I decided to spend the time to get this out :) That being said, please don't ask us every day. You will get notified when the release is out. |
I hate to ask, but please share an update. It looks like our best bet is to upgrade to v4 to get this fixed in a timely fashion. |
No news, yet, sorry. You can always use the |
Any news |
Yeah, probably around December 10, hopefully. |
Hi, will it be released today? |
I sure hope so, it's late in USA so I haven't checked with @mdo yet. |
Sorry for postponing this, I honestly hope it's the last time, we will release it on Thursday and then release v4.2. |
Still on target for today's release? |
Yup, waiting for @mdo and we'll start. |
Awesome, looking forward to it! |
Hi, it's been a couple hours since the last question regarding ETA. Do I have time to grab lunch before this is done? Thanks 👍 :) |
We just merged #27288—release inbound! |
Hello @coliff The above URL for bootstrap.min.js is going to 404. please, can you share with me the link with X-SS fix? |
Hi @OwaisDG bootstrap 3.4.0 is out now. |
Hi all, opening this to track a possible v3.4 final release. It would be great to have this, as the v3.4-dev branch includes #23687, which fixed a few xss vulnerabilities.
There are also a few remaining v3 issues, but it's not clear to me how critical they are.
The text was updated successfully, but these errors were encountered: