DependencyTrack / DependencyTrack/dependency-track

Outdated Bootstrap Framework (Bootstrap 4.6.2) Detected

Open
#6,625 0 comments 0 reactions 0 assignees View on GitHub
defect in triage
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
8h 39m
Merged PRs (30d)
237

Description

### Current Behavior

**Info**:
- Bootstrap 4.3.1 is an outdated release that is no longer actively maintained and may be affected by publicly disclosed security vulnerabilities addressed in later versions
- Failure to maintain third-party dependencies may result in exposure to publicly disclosed vulnerabilities, increased remediation effort, and non-compliance with secure software maintenance practices.
- The installation of Boostrap detected on the remote host is no longer supported. Lack of support implies that no new security patches for the product will be released by the vendor. As a result, it is likely to contain security vulnerabilities.

**See Also**
- https://getbootstrap.com/docs/4.6/end-of-life/
- https://www.tenable.com/plugins/was/114902

### Steps to Reproduce

Consider upgrading to:
- Bootstrap 5.3 (preferred for long-term support).

### Expected Behavior

Consider upgrading to:
- Bootstrap 5.x (preferred for long-term support).

### Dependency-Track Version

5.x

### Browser

Google Chrome

### Checklist

- [x] I have read and understand the [contributing guidelines](https://github.com/DependencyTrack/dependency-track/blob/main/CONTRIBUTING.md#filing-issues)
- [x] I have checked the [existing issues](https://github.com/DependencyTrack/dependency-track/issues) for whether this defect was already reported

Contributor guide

Open the contributing guide

Research direction

Start by locating the Bootstrap 4.x dependency and the frontend assets that use it, then review the Bootstrap 5.x migration requirements. Update the dependency and any affected frontend references, and verify that the application builds and the reported outdated Bootstrap version is no longer detected.

Written by the indexing model from the issue text.

Assessment

Tech stack
bootstrap
Domain
frontend, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.