Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump to Quill Version 1.3.7 #34

Merged
merged 2 commits into from
Feb 9, 2021
Merged

Conversation

cdesch
Copy link
Contributor

@cdesch cdesch commented Feb 5, 2021

Bump to Quill Version 1.3.7 - This version of Quill fixes Quill Vuln slab/quill#2438

The current version of Quill (1.3.6) that django-quill-editor uses has an active vulnerability open. Bumping to Quill version 1.3.7 fixes the issue.

Here is the change commit to fix the vuln in Quill slab/quill#2439

The Vuln is described here: https://ossindex.sonatype.org/vuln/d96c07dd-81f9-41f6-b2bd-531143bcaeab

Bump to Quill Version 1.3.7 - This version of Quill fixes Quill Vuln slab/quill#2438

Here is the change commit to fix the vuln in Quill slab/quill#2439

The Vuln is described here: https://ossindex.sonatype.org/vuln/d96c07dd-81f9-41f6-b2bd-531143bcaeab
@cdesch
Copy link
Contributor Author

cdesch commented Feb 5, 2021

@LeeHanYeong Please consider merging this fix into the master branch and incrementing the django-quill-editor from 0.1.16 to 0.1.17 and publishing a new package to PyPi.

@LeeHanYeong LeeHanYeong merged commit 1ee92ab into LeeHanYeong:master Feb 9, 2021
LeeHanYeong pushed a commit that referenced this pull request Dec 8, 2021
* Bump to Quill Version 1.3.7

Bump to Quill Version 1.3.7 - This version of Quill fixes Quill Vuln slab/quill#2438

Here is the change commit to fix the vuln in Quill slab/quill#2439

The Vuln is described here: https://ossindex.sonatype.org/vuln/d96c07dd-81f9-41f6-b2bd-531143bcaeab

* Adding JS/CSS include instructions from README.md

Resolves issue [#33](#33)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants