aboutsummaryrefslogtreecommitdiff
path: root/doc/bugs/outdated_jquery-ui.mdwn
diff options
context:
space:
mode:
Diffstat (limited to 'doc/bugs/outdated_jquery-ui.mdwn')
-rw-r--r--doc/bugs/outdated_jquery-ui.mdwn6
1 files changed, 6 insertions, 0 deletions
diff --git a/doc/bugs/outdated_jquery-ui.mdwn b/doc/bugs/outdated_jquery-ui.mdwn
index 41d3f1b21..bcd44e27d 100644
--- a/doc/bugs/outdated_jquery-ui.mdwn
+++ b/doc/bugs/outdated_jquery-ui.mdwn
@@ -8,3 +8,9 @@ Amitai gets there first.
It doesn't look as though we actually use the vulnerable functionality.
--[[smcv]]
+
+> This is more complicated than it looked at first glance because both
+> jquery and jquery-ui have broken API since the version we embed,
+> and we also ship other jquery plugins for [[plugins/attachment]].
+> Perhaps someone who knows jquery could check compatibility and
+> propose a branch? --[[smcv]]