Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

highlight.js 9 EOL #23932

Open
aimador opened this issue Dec 13, 2021 · 9 comments
Open

highlight.js 9 EOL #23932

aimador opened this issue Dec 13, 2021 · 9 comments
Assignees

Comments

@aimador
Copy link

aimador commented Dec 13, 2021

Description:

While building the latest RC release on CentOS 7 I get the following information:

----------------------------------

Verion 9 of Highlight.js has reached EOL. It will no longer
be supported or receive security updates in the future.
Please upgrade to version 10 or encourage your indirect
dependencies to do so.

For more info:

highlightjs/highlight.js#2877
https://github.com/highlightjs/highlight.js/blob/master/VERSION_10_UPGRADE.md

----------------------------------

The build works, but highlight.js should be updated IMHO.

Steps to reproduce:

  1. Build v. 4.2.1
  2. Scroll back up and check the build logs.

Expected behavior:

No EOL warning.

Actual behavior:

see above

Server Setup Information:

  • Version of Rocket.Chat Server: 4.2.1
  • Operating System: CentOS 7
  • Deployment Method: tar / local install
  • Number of Running Instances: 1
  • DB Replicaset Oplog: ON, but only 1 instance
  • NodeJS Version: 12.22.1
  • MongoDB Version: 4.2

Client Setup Information

  • Desktop App or Browser Version: RC 3.5.7
  • Operating System: Win10
@tete2soja
Copy link

Hello,

The warning is still here for the last minor release 4.3.2.

@Vringe
Copy link

Vringe commented Feb 15, 2022

Still present in 4.4.2

@lyz-code
Copy link

lyz-code commented Mar 14, 2022

And in 4.5.2

@Vringe
Copy link

Vringe commented Mar 15, 2022

Version 9.18.5 (which RC is using) and also Version 10 are both EOL and do have known vulnerabilities.
Upgrade to Version 11 is necessary.

See https://github.com/highlightjs/highlight.js/blob/main/SECURITY.md

@danel1
Copy link

danel1 commented Mar 21, 2022

@debdutdeb @dudanogueira @tassoevan @sampaiodiego Could someone please take a look at this? This is security relevant and completely ignored....

@CAberry
Copy link

CAberry commented Jul 22, 2022

Hello,

Rocket version 4.8.2

In admin settings -> message , link to version 9.18.5 is still present so I guess version 11 is not implemented yet
image

highlight is pretty useful, you dev people know it better then anyone ;-)

Regards,

@wreiske
Copy link
Contributor

wreiske commented Mar 14, 2023

This is still the case in 6.0.0.

@wreiske
Copy link
Contributor

wreiske commented Jun 5, 2023

This is still the case in 6.2.2.

@Vringe
Copy link

Vringe commented Jan 19, 2024

Still used in 6.5.3

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

8 participants