<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Suggestions on how we can upgrade the jquery version in this minified js file? in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/Suggestions-on-how-we-can-upgrade-the-jquery-version-in-this/m-p/582922#M10333</link>
    <description>&lt;P&gt;Hi Experts,&lt;/P&gt;
&lt;P&gt;We performed "&lt;SPAN&gt;check_for_vulnerable_javascript_library_usage" check for our add-on app. As per report we need to upgrade jquery version.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We have one common.js file which is minified js and located in following directory -&amp;nbsp;appserver/static/js/build/common.js&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Could you please suggest how can we upgrade the jquery version in this minified js file?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I went through article - &lt;A href="https://dev.splunk.com/enterprise/docs/developapps/visualizedata/updatejquery/?_ga=2.112247757.872217667.1643345201-285550.1643345200" target="_blank" rel="noopener"&gt;https://dev.splunk.com/enterprise/docs/developapps/visualizedata/updatejquery/?_ga=2.112247757.872217667.1643345201-285550.1643345200&lt;/A&gt; but the steps mentioned here aren't applicable in my case. I am add-on app's tgz file and need to update the jquery version.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Appreciate any inputs on this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;Saurabh&lt;/P&gt;</description>
    <pubDate>Wed, 09 Feb 2022 19:55:50 GMT</pubDate>
    <dc:creator>teamdruva</dc:creator>
    <dc:date>2022-02-09T19:55:50Z</dc:date>
    <item>
      <title>Suggestions on how we can upgrade the jquery version in this minified js file?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Suggestions-on-how-we-can-upgrade-the-jquery-version-in-this/m-p/582922#M10333</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;
&lt;P&gt;We performed "&lt;SPAN&gt;check_for_vulnerable_javascript_library_usage" check for our add-on app. As per report we need to upgrade jquery version.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We have one common.js file which is minified js and located in following directory -&amp;nbsp;appserver/static/js/build/common.js&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Could you please suggest how can we upgrade the jquery version in this minified js file?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I went through article - &lt;A href="https://dev.splunk.com/enterprise/docs/developapps/visualizedata/updatejquery/?_ga=2.112247757.872217667.1643345201-285550.1643345200" target="_blank" rel="noopener"&gt;https://dev.splunk.com/enterprise/docs/developapps/visualizedata/updatejquery/?_ga=2.112247757.872217667.1643345201-285550.1643345200&lt;/A&gt; but the steps mentioned here aren't applicable in my case. I am add-on app's tgz file and need to update the jquery version.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Appreciate any inputs on this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;Saurabh&lt;/P&gt;</description>
      <pubDate>Wed, 09 Feb 2022 19:55:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Suggestions-on-how-we-can-upgrade-the-jquery-version-in-this/m-p/582922#M10333</guid>
      <dc:creator>teamdruva</dc:creator>
      <dc:date>2022-02-09T19:55:50Z</dc:date>
    </item>
    <item>
      <title>Update jquery version</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Suggestions-on-how-we-can-upgrade-the-jquery-version-in-this/m-p/583005#M10334</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/90723"&gt;@diogofgm&lt;/a&gt;&amp;nbsp;could you please help here. Appreciate your inputs.&lt;/P&gt;</description>
      <pubDate>Sat, 29 Jan 2022 04:05:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Suggestions-on-how-we-can-upgrade-the-jquery-version-in-this/m-p/583005#M10334</guid>
      <dc:creator>teamdruva</dc:creator>
      <dc:date>2022-01-29T04:05:12Z</dc:date>
    </item>
    <item>
      <title>Re: Update jquery version</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Suggestions-on-how-we-can-upgrade-the-jquery-version-in-this/m-p/583077#M10335</link>
      <description>&lt;P&gt;Is there any information on the results of the app inspect? I believe it should point to where should the problem be.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jan 2022 12:24:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Suggestions-on-how-we-can-upgrade-the-jquery-version-in-this/m-p/583077#M10335</guid>
      <dc:creator>diogofgm</dc:creator>
      <dc:date>2022-01-31T12:24:42Z</dc:date>
    </item>
    <item>
      <title>Re: Update jquery version</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Suggestions-on-how-we-can-upgrade-the-jquery-version-in-this/m-p/583115#M10336</link>
      <description>&lt;P&gt;Thanks for your response. Initially I got following error:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;{
                                    "result": "warning",
                                    "message": "3rd party CORS request may execute\nparseHTML() executes scripts in event handlers\njQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution\nRegex in its jQuery.htmlPrefilter sometimes may introduce XSS\nRegex in its jQuery.htmlPrefilter sometimes may introduce XSS\nreDOS - regular expression denial of service\n",
                                    "message_filename": "/opt/app7hugi7qy/TA-druva/appserver/static/js/build/common.js",
                                    "message_line": null
                                }&lt;/LI-CODE&gt;&lt;P&gt;This is related to upgrade of JQuery version to 3.5.0.&lt;/P&gt;&lt;P&gt;Since I had minified javascript (path - appserver/static/js/build/common.js), I couldn't find jquery version import anywhere but I found "contrib/jquery-2.1.0" in this file and replaced it with "contrib/jquery-3.5.0".&lt;/P&gt;&lt;P&gt;After running AppInspect on the updated app, getting following warning:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;{
                    "description": "Checks related to JavaScript usage.",
                    "name": "check_javascript_usage",
                    "checks": [
                        {
                            "description": "Detect usage of JavaScript libraries with known vulnerabilities.",
                            "name": "check_for_vulnerable_javascript_library_usage",
                            "tags": [
                                "cloud",
                                "future",
                                "jquery",
                                "security"
                            ],
                            "result": "warning",
                            "messages": [
                                {
                                    "result": "warning",
                                    "message": "reDOS - regular expression denial of service\n",
                                    "message_filename": "/opt/appdlobc8sm/TA-druva/appserver/static/js/build/common.js",
                                    "message_line": null
                                }
                            ]
                        }
                    ]
                }&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;Usually the error "reDOS - regular expression denial of service” in jQuery is related to jQuery-validation library but we aren’t using any such library. Is it fine to submit the app with this warning?&lt;/DIV&gt;&lt;DIV class=""&gt;If not, kindly suggest how to fix this issue.&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Mon, 31 Jan 2022 17:03:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Suggestions-on-how-we-can-upgrade-the-jquery-version-in-this/m-p/583115#M10336</guid>
      <dc:creator>teamdruva</dc:creator>
      <dc:date>2022-01-31T17:03:48Z</dc:date>
    </item>
    <item>
      <title>Re: Update jquery version</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Suggestions-on-how-we-can-upgrade-the-jquery-version-in-this/m-p/583534#M10337</link>
      <description>&lt;P&gt;Cross posting with&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Developing-for-Splunk-Enterprise/How-do-I-address-quot-check-for-vulnerable-javascript-library/m-p/582985#M9695" target="_self"&gt;How do I address "check_for_vulnerable_javascript_library_usage" errors in AppInspect?&lt;/A&gt;which sounds like the same question. I'm also hunting for some SMEs who can help.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Feb 2022 11:53:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Suggestions-on-how-we-can-upgrade-the-jquery-version-in-this/m-p/583534#M10337</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2022-02-03T11:53:43Z</dc:date>
    </item>
    <item>
      <title>Re: Update jquery version</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Suggestions-on-how-we-can-upgrade-the-jquery-version-in-this/m-p/583620#M10338</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/242575"&gt;@teamdruva&lt;/a&gt;&amp;nbsp;I talked to the cloud vetting folks. As it's a 'warning' go ahead and submit the app. They know it's coming and will give it a look as part of their manual review process.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Feb 2022 18:12:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Suggestions-on-how-we-can-upgrade-the-jquery-version-in-this/m-p/583620#M10338</guid>
      <dc:creator>doc_holiday</dc:creator>
      <dc:date>2022-02-03T18:12:47Z</dc:date>
    </item>
    <item>
      <title>Re: Update jquery version</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Suggestions-on-how-we-can-upgrade-the-jquery-version-in-this/m-p/583621#M10339</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;XPOST from&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Developing-for-Splunk-Enterprise/How-do-I-address-quot-check-for-vulnerable-javascript-library/m-p/582985#M9695" target="_self"&gt;How do I address "check_for_vulnerable_javascript_library_usage" errors in AppInspect?&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/242575"&gt;@teamdruva&lt;/a&gt;&amp;nbsp;I talked to the cloud vetting folks. As it's a 'warning' go ahead and submit the app. They know it's coming and will give it a look as part of their manual review process.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Feb 2022 18:13:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Suggestions-on-how-we-can-upgrade-the-jquery-version-in-this/m-p/583621#M10339</guid>
      <dc:creator>doc_holiday</dc:creator>
      <dc:date>2022-02-03T18:13:50Z</dc:date>
    </item>
    <item>
      <title>Re: Update jquery version</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Suggestions-on-how-we-can-upgrade-the-jquery-version-in-this/m-p/584302#M10340</link>
      <description>&lt;P&gt;As you can imagine, security related things are hard to get info on. Nonetheless, it was pointed&amp;nbsp;out to me that this is a warning, not a failure, and as such it shouldn't be an impediment to building the app. I'll continue to see if I can get more info on this.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Feb 2022 14:22:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Suggestions-on-how-we-can-upgrade-the-jquery-version-in-this/m-p/584302#M10340</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2022-02-09T14:22:19Z</dc:date>
    </item>
    <item>
      <title>Re: Update jquery version</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Suggestions-on-how-we-can-upgrade-the-jquery-version-in-this/m-p/585029#M10341</link>
      <description>&lt;P&gt;If the common.js came from the &lt;A href="https://splunkbase.splunk.com/app/2962/" target="_self"&gt;Splunk Add-on Builder&lt;/A&gt; then you can ignore it for now. We're investigating false positives from that and we (Splunk) needs to provide a fix to either the&amp;nbsp;check_for_vulnerable_javascript_library_usage or the code that&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/2962/" target="_self"&gt;Splunk Add-on Builder&lt;/A&gt;&amp;nbsp;adds to your app.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Feb 2022 19:15:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Suggestions-on-how-we-can-upgrade-the-jquery-version-in-this/m-p/585029#M10341</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2022-02-14T19:15:46Z</dc:date>
    </item>
    <item>
      <title>Re: Update jquery version</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Suggestions-on-how-we-can-upgrade-the-jquery-version-in-this/m-p/587650#M10342</link>
      <description>&lt;P&gt;&lt;A href="https://community.splunk.com/t5/user/viewprofilepage/user-id/90723" target="_blank"&gt;@diogofgm&lt;/A&gt;&amp;nbsp;Do you have a solution for this issue? Our add-on is created by the add-on builder and we get an issue with common.js and Splunk Cloud Support colleagues have rejected the add-on. What should be the next step?&lt;/P&gt;</description>
      <pubDate>Fri, 04 Mar 2022 13:24:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Suggestions-on-how-we-can-upgrade-the-jquery-version-in-this/m-p/587650#M10342</guid>
      <dc:creator>swati_singh</dc:creator>
      <dc:date>2022-03-04T13:24:38Z</dc:date>
    </item>
    <item>
      <title>Re: Suggestions on how we can upgrade the jquery version in this minified js file?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Suggestions-on-how-we-can-upgrade-the-jquery-version-in-this/m-p/587680#M10343</link>
      <description>&lt;P&gt;Sometimes this is a false-positive from Add-on Builder because it does not prune legacy files on Export.&amp;nbsp; We found that by following this procedure, the Add-on Builder will essentially fix itself by pruning unrequired JS files:&lt;/P&gt;&lt;P&gt;- Export the app from Add-on Builder&lt;/P&gt;&lt;P&gt;- Delete the app from Add-on Builder&lt;/P&gt;&lt;P&gt;- Import the app to Add-on Builder&lt;/P&gt;&lt;P&gt;- Package and download the app from the "Validate &amp;amp; Package" dashboard&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This should remove the common.js from the package if it is not relevant.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Mar 2022 16:39:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Suggestions-on-how-we-can-upgrade-the-jquery-version-in-this/m-p/587680#M10343</guid>
      <dc:creator>jowenssi</dc:creator>
      <dc:date>2022-03-04T16:39:55Z</dc:date>
    </item>
    <item>
      <title>Re: Suggestions on how we can upgrade the jquery version in this minified js file?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Suggestions-on-how-we-can-upgrade-the-jquery-version-in-this/m-p/587682#M10344</link>
      <description>&lt;P&gt;One thing I forgot to note.&amp;nbsp; This appears to be fixed in Add-on Builder version 4.1.0 but you will need to perform the export/import process if you upgrade the app in-place.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Mar 2022 16:42:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Suggestions-on-how-we-can-upgrade-the-jquery-version-in-this/m-p/587682#M10344</guid>
      <dc:creator>jowenssi</dc:creator>
      <dc:date>2022-03-04T16:42:37Z</dc:date>
    </item>
    <item>
      <title>Re: Suggestions on how we can upgrade the jquery version in this minified js file?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Suggestions-on-how-we-can-upgrade-the-jquery-version-in-this/m-p/587706#M10345</link>
      <description>&lt;P&gt;Nailed it! I tried to write a clear message about the collaboration we did at &lt;A href="https://community.splunk.com/t5/Developing-for-Splunk-Cloud/How-to-fix-AppInspect-check-for-vulnerable-javascript-library/m-p/587702" target="_self"&gt;How to fix AppInspect check_for_vulnerable_javascript_library_usage from Add-on Builder content&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Mar 2022 19:34:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Suggestions-on-how-we-can-upgrade-the-jquery-version-in-this/m-p/587706#M10345</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2022-03-04T19:34:43Z</dc:date>
    </item>
    <item>
      <title>Re: Suggestions on how we can upgrade the jquery version in this minified js file?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Suggestions-on-how-we-can-upgrade-the-jquery-version-in-this/m-p/587726#M10346</link>
      <description>&lt;P&gt;Upgrading the add-on builder and exporting the add-on from there fixed the issue.&lt;/P&gt;</description>
      <pubDate>Sat, 05 Mar 2022 05:53:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Suggestions-on-how-we-can-upgrade-the-jquery-version-in-this/m-p/587726#M10346</guid>
      <dc:creator>swati_singh</dc:creator>
      <dc:date>2022-03-05T05:53:51Z</dc:date>
    </item>
  </channel>
</rss>

