1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Won't Fix Yahoo YUI 2 - Need to update

Discussion in 'Resolved Bug Reports' started by Adam Howard, Jul 27, 2012.

  1. Adam Howard

    Adam Howard Well-Known Member

    This isn't a suggestion, nor is it a comment. So I'm going to list this as a bug.

    Yahoo YUI 2 is reaching end of life
    http://developer.yahoo.com/yui/2/

    And even if you settle on ignoring this; you have version 2.7.0 used xenforo_reset.css (not sure where else)


    Last v2 release was 2.8.2 which was released on October 25, 2010 and was only a security update (which affected version 2.4.0 through 2.8.1).

    Please for the security of your site (and customers), update.
     
  2. Adam Howard

    Adam Howard Well-Known Member

    Found some old YUI here too

    xenforo_basehtml.css

    That seems to be the end of the template where YUI are used.

    Have yet to check the files (hard code)
     
  3. simbolo

    simbolo Well-Known Member

    I don't believe it is a security concern as those are css files. They do use the third party Minify library but even that they only use it to shrink css files /library/XenForo/CssOutput.php and that's done without the yuicompressor jar. Thus I don't think there's a reason for concern here.
     
    Adam Howard likes this.
  4. ragtek

    ragtek Guest

    Yep.
    The security issues where affecting only the swf files http://yuilibrary.com/support/2.8.2/#dropins
     
    Adam Howard likes this.
  5. Adam Howard

    Adam Howard Well-Known Member

  6. Robbo

    Robbo Well-Known Member

    They barely use any of the library. The parts they use I very highly doubt ever change. There is no need to update a thing.
     
    SneakyDave likes this.
  7. Mike

    Mike XenForo Developer Staff Member

    Yeah, no plans to update this - no security issue in the base CSS and there's no point potentially breaking anything with this.
     
    Slavik likes this.

Share This Page