Skip to content

Conversation

@NOXCIS
Copy link
Owner

@NOXCIS NOXCIS commented Nov 8, 2025

snyk-top-banner

Snyk has created this PR to upgrade bootstrap from 5.3.3 to 5.3.8.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 5 versions ahead of your current version.

  • The recommended version was released 2 months ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-CROSSSPAWN-8303230
222 Proof of Concept
medium severity Improper Input Validation
SNYK-JS-NANOID-8492085
222 No Known Exploit
medium severity Symlink Attack
SNYK-JS-TMP-11501554
222 Proof of Concept
low severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BRACEEXPANSION-9789073
222 Proof of Concept
low severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BRACEEXPANSION-9789073
222 Proof of Concept
critical severity Predictable Value Range from Previous Values
SNYK-JS-FORMDATA-10841150
222 Proof of Concept
Release notes
Package name: bootstrap
  • 5.3.8 - 2025-08-26

    What's Changed

    Dependencies

    New Contributors

    Full Changelog: v5.3.7...v5.3.8

  • 5.3.7 - 2025-06-17

    📚 Documentation

    • Fixed broken "View on GitHub" URLs
    • Corrected HTML <head> content generated by the "Download examples" button
    • Refined sanitizer documentation for clarity and completeness
    • Improved accessibility in the "On this page" table of contents and section heading anchor links
    • Relocated ads to the right sidebar to minimize content reflow
    • Added a new section on the Download page for the Intelissence extension
    • Clarified the "Via JavaScript" usage example for Accordion Collapse
    • Made internal documentation improvements to support future maintenance (no visible user impact)
    • Mention CDN integrity and crossorigin attributes in introduction page
    • Enhance floating labels placeholder usage description
    • Add example of showing dynamic range value with output

    🎨 Sass

    • Consolidated multiple 'none' values in the box-shadow Sass mixin for cleaner output

    🤖 JavaScript

    • Fixed popover and tooltip behavior with a trigger: "hover click" configuration

    🤝 Contributions

    • Added recommended VSCode extensions and settings configuration to the repository
  • 5.3.6 - 2025-05-05

    Highlights

    • Ported the docs from Hugo to Astro for our own sanity!
    • Added usage docs for Accordion JavaScript
    • Prevent .visually-hidden overflowing children to become focusable
    • Limit .card-group selectors to immediate children to fix some inheritance issues

    Changes

    New Contributors

    Full Changelog: v5.3.5...v5.3.6

  • 5.3.5 - 2025-04-04

    Hot fix for a regression from upstream in Autoprefixer.

    What's Changed

    Full Changelog: v5.3.4...v5.3.5

  • 5.3.4 - 2025-04-03

    Changes

    • #40888: Dependabot: switch to grouped updates

    🚀 Features

    • #41299: Typo fixed
    • #41187: Docs: mention removal of util.js in migration guide
    • #41228: Docs: Simplify ids for checks, radios and switches
    • #41150: Update fixtureId to FIXTURE_ID for consistency
    • #40965: Docs: Use <article> element for example cards
    • #40932: Docs: add ngx-bootstrap to JavaScript frameworks list
    • #40790: Docs: Drop .grid where it sh...

Snyk has created this PR to upgrade bootstrap from 5.3.3 to 5.3.8.

See this package in npm:
bootstrap

See this project in Snyk:
https://app.snyk.io/org/shamarakeillee/project/2088e7cc-7f0f-490c-9bb3-b75de53f57ed?utm_source=github&utm_medium=referral&page=upgrade-pr
@NOXCIS NOXCIS closed this Jan 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants