On Wed, Jul 18, 2018 at 1:32 AM Christopher <ctubb...@fedoraproject.org> wrote:
> It is my intention to orphan js-jquery1 and js-jquery2. Does anybody want > to take them over? > > These very old versions of jQuery have security issues that I do not have > time nor expertise to maintain. Upstream's last patch for either of these > occurred over 2 years ago. Everybody should be using jQuery 3 by now > (js-jquery). Anything older is insecure and unsafe. > > Personally, I think they should be retired, but I don't know (or have time > to check) to see if that would cause problems for anybody. > > I've orphaned js-jquery1 and js-jquery2. For those packages which still depend on them, I strongly recommend that you update your package to depend on the latest version of js-jquery. Also, as an aside, I noticed that jquery1 appears to be bundled into nodejs-flot; that should be fixed. In fact, I think nodejs-flot and ghc-js-flot need to coordinate to remove the duplication, since they are both are packaging flot... but in very different ways.
_______________________________________________ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org/message/MI7W7TT3MUGMQTLYZYE5FKXUJCKFUXU7/