Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update to newer version of TimelineJS #27

Open
krabina opened this issue Nov 9, 2022 · 5 comments
Open

Update to newer version of TimelineJS #27

krabina opened this issue Nov 9, 2022 · 5 comments

Comments

@krabina
Copy link

krabina commented Nov 9, 2022

The TimelineJS verson used is currently at 3.6.5 https://github.com/ProfessionalWiki/ModernTimeline/blob/master/resources/vendor/timeline.js
while the original repo is on version 3.9.0
](https://github.com/NUKnightLab/TimelineJS3/blob/master/CHANGELOG.md)

At some point we should update to a more recent version,

@Seb35
Copy link
Contributor

Seb35 commented Feb 7, 2023

There is a security issue on timeline.js 3.6.5 (CVE-2020-15092) so it would be better to update the library as soon as possible.
We searched with @NavidBoy (apprentice at Wiki Valley) the new version of the library but we didn’t find in the same distribution form (1 JS file bundling multiple libraries). @JeroenDeDauw : do you know where to find this or how to compile it?

@krabina
Copy link
Author

krabina commented Feb 7, 2023

From what I understand, the issue is mostly related to using Google Docs. One would have to put malicious content in the wiki in order to exploit this, so I guess it is not a big problem for this extension.

But anyway it would be great to update the library.

@krabina
Copy link
Author

krabina commented Feb 7, 2023

Maybe also this helps: https://github.com/NUKnightLab/TimelineJS-Wordpress-Plugin

@Seb35
Copy link
Contributor

Seb35 commented Feb 7, 2023

Digging deeper, I found this doc, and the compiled versions are explained here, so the new compiled version is downloadable here. It is now minified (at the contrary of 3.6.5).

@JeroenDeDauw
Copy link
Member

Correct link: https://cdn.knightlab.com/libs/timeline3/3.9.2/timeline3.zip

PR with new version welcome. Good to test the extension after upgrading the lib, since they might have made breaking changes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants