On Wed, Jul 18, 2018 at 1:32 AM Christopher ctubbsii@fedoraproject.org wrote:
It is my intention to orphan js-jquery1 and js-jquery2. Does anybody want to take them over?
These very old versions of jQuery have security issues that I do not have time nor expertise to maintain. Upstream's last patch for either of these occurred over 2 years ago. Everybody should be using jQuery 3 by now (js-jquery). Anything older is insecure and unsafe.
Personally, I think they should be retired, but I don't know (or have time to check) to see if that would cause problems for anybody.
I've orphaned js-jquery1 and js-jquery2.
For those packages which still depend on them, I strongly recommend that you update your package to depend on the latest version of js-jquery.
Also, as an aside, I noticed that jquery1 appears to be bundled into nodejs-flot; that should be fixed. In fact, I think nodejs-flot and ghc-js-flot need to coordinate to remove the duplication, since they are both are packaging flot... but in very different ways.