Uploaded image for project: 'Moodle'
  1. Moodle
  2. MDL-73610

Upgrade xmldom dev dependency

XMLWordPrintable

    • MOODLE_311_STABLE, MOODLE_400_STABLE
    • MOODLE_311_STABLE, MOODLE_39_STABLE, MOODLE_400_STABLE, MOODLE_401_STABLE
    • MDL-73610_401
    • Hide

      Run the following commands in Moodle's root directory and verify all them work ok:

      1. nvm use (requires to have nvm installed).
      2. npm ci
      3. npx grunt
      4. npx grunt jsconfig (All branches but 39_STABLE)
      5. npx grunt jsdoc (All branches but 39_STABLE)
      6. npx grunt upgradablelibs (Only in master)
      Show
      Run the following commands in Moodle's root directory and verify all them work ok: nvm use (requires to have nvm installed). npm ci npx grunt npx grunt jsconfig (All branches but 39_STABLE) npx grunt jsdoc (All branches but 39_STABLE) npx grunt upgradablelibs (Only in master)

      A moderated-severity report @ github:

      https://github.com/moodle/moodle/security/dependabot (CVE-2021-32796)

      has been reported about the xmldom package and it needs to be upgraded to version 0.7.0 (right now using 0.6.0).

      For sure this is not critical as far as we only use it as development (component library) requirement, but better get it fixed.

            stronk7 Eloy Lafuente (stronk7)
            stronk7 Eloy Lafuente (stronk7)
            Andrew Lyons Andrew Lyons
            Sara Arjona (@sarjona) Sara Arjona (@sarjona)
            Kim Jared Lucas Kim Jared Lucas
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved:

                Estimated:
                Original Estimate - 0 minutes
                0m
                Remaining:
                Remaining Estimate - 0 minutes
                0m
                Logged:
                Time Spent - 3 hours, 21 minutes
                3h 21m

                  Error rendering 'clockify-timesheets-time-tracking-reports:timer-sidebar'. Please contact your Jira administrators.