[GH-ISSUE #23] use xstatic packages for jquery, bootstrap, etc. #23

Open
opened 2026-02-26 09:34:59 +03:00 by kerem · 5 comments
Owner

Originally created by @ThomasWaldmann on GitHub (Oct 22, 2013).
Original GitHub issue: https://github.com/nsupdate-info/nsupdate.info/issues/23

ThomasWaldmann wrote:
they offer a little metadata including CDN information, additional to the static files, all installable via pypi.

Originally created by @ThomasWaldmann on GitHub (Oct 22, 2013). Original GitHub issue: https://github.com/nsupdate-info/nsupdate.info/issues/23 ThomasWaldmann wrote: they offer a little metadata including CDN information, additional to the static files, all installable via pypi.
Author
Owner

@ThomasWaldmann commented on GitHub (Oct 22, 2013):

asmaps wrote:
CDN is good for now. For self-serving put them in static

<!-- gh-comment-id:26768374 --> @ThomasWaldmann commented on GitHub (Oct 22, 2013): asmaps wrote: CDN is good for now. For self-serving put them in static
Author
Owner

@ThomasWaldmann commented on GitHub (Oct 23, 2013):

if we just put it in static, we have 3rd party stuff in our project, not nice.

so let's just use xstatic, it was invented just for that and is low-fat.

<!-- gh-comment-id:26877868 --> @ThomasWaldmann commented on GitHub (Oct 23, 2013): if we just put it in static, we have 3rd party stuff in our project, not nice. so let's just use xstatic, it was invented just for that and is low-fat.
Author
Owner

@ThomasWaldmann commented on GitHub (Nov 12, 2013):

this task can be held back as long as we just use all 3rd party stuff from the CDNs.

but as soon as we have a reason to serve that stuff on our own, it should be done like described in this task.

<!-- gh-comment-id:28293438 --> @ThomasWaldmann commented on GitHub (Nov 12, 2013): this task can be held back as long as we just use all 3rd party stuff from the CDNs. but as soon as we have a reason to serve that stuff on our own, it should be done like described in this task.
Author
Owner
<!-- gh-comment-id:61077455 --> @elnappo commented on GitHub (Oct 30, 2014): one reason is: http://www.heise.de/security/meldung/Nach-Hack-Verdacht-jQuery-Entwickler-untersuchen-ihre-Server-2402550.html in english: http://www.riskiq.com/resources/blog/jquerycom-malware-attack-puts-privileged-enterprise-it-accounts-risk
Author
Owner

@ThomasWaldmann commented on GitHub (Oct 30, 2014):

Yeah (although in that specific case they said that the CDN isn't affected - but it could happen...).

<!-- gh-comment-id:61091615 --> @ThomasWaldmann commented on GitHub (Oct 30, 2014): Yeah (although in that specific case they said that the CDN isn't affected - but it could happen...).
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/nsupdate.info-nsupdate-info#23
No description provided.