<div dir="ltr">Thanks for the reply Scott.<div>I'll go ahead and file an issue in Jira. I just tagged/made a release in the duo_java github repo called DuoWeb-2.6 </div><div>This change is not to fix a security vulnerability. It is just providing additional functionality to use with our service. So getting in with the release of 3.4 sounds great. The current javascript file won't stop functioning properly at any point, so again, no need to patch.</div><div><br></div><div>Just to provide some clarity on what the change is. We are updating the javascript file that lives in java-identity-provider/idp-war/src/main/webapp/js/Duo-Web-v2.min.js</div><div>Currently this file in the shibboleth repo is what we refer to as version 2.3. We are going to update it to version2.6 by replacing it with the javascript file from the latest tagged release of duo_java DuoWeb-2.6</div><div>I noticed you've done it once before when updating from 2.0 to 2.3 <a href="http://git.shibboleth.net/view/?p=java-identity-provider.git;a=commit;h=d6406ba42b64ff7efdcd6f2fef5849fc4fd363c9">http://git.shibboleth.net/view/?p=java-identity-provider.git;a=commit;h=d6406ba42b64ff7efdcd6f2fef5849fc4fd363c9</a><br></div><div>So I'm hoping it will be a very similar process this time.</div><div><br></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Mon, Jun 12, 2017 at 12:54 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">On 6/12/17, 11:00 AM, "dev on behalf of Xander Desai" <<a href="mailto:dev-bounces@shibboleth.net">dev-bounces@shibboleth.net</a> on behalf of <a href="mailto:xdesai@duo.com">xdesai@duo.com</a>> wrote:<br>
<br>
> I'm an engineer at Duo Security and we have a new update to the Duo WebSDK that we'd like to roll out to the Duo plugin for<br>
> Shibboleth. Currently Shibboleth is on WebSDK v2.3 and we'd like to get on the latest v2.6.<br>
<br>
</span>I'm still not seeing the projects in github with clearly marked and tagged releases, can you maybe give me a pointer to were there's a piece of code labeled with that version?<br>
<br>
Or are you saying that your back-end API has that version, and the untagged/unversioned code in github is now altered to reflect that?<br>
<br>
In which case, we really need to see that code versioned and tagged.<br>
<span class=""><br>
> What is the best way for me to assist with this change? Is a pull request the appropriate way to handle this update?<br>
<br>
</span>You can file an issue in our Jira, but our normal course of work includes reviewing dependencies for updates when we do new releases, and because it's a core feature people rely on it would get updated as a normal matter of business when 3.4 is released. If there were a security issue, then we would do it as a patch release because it was necessary.<br>
<br>
The notion of a cloud dependency is not one we have a lot of past experience with, but a compatibility issue where the code would stop working at some point in between normal upgrades would require us to do a patch as well, which I'm hoping isn't the case here but if I've missed some announcement, I'll take a look. I'll make sure I'm on the right lists, which I'm probably not.<br>
<br>
It's definitely a problem for us to be asked to update to unreleased code. That means a signed tag in github, if that's where the code lives.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:dev-unsubscribe@shibboleth.net">dev-unsubscribe@shibboleth.net</a><br>
</font></span></blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><table border="0" cellpadding="0" cellspacing="0" style="border-collapse:collapse;border-spacing:0px;max-width:100%;color:rgb(51,51,51);font-family:'Helvetica Neue',Helvetica,Arial,sans-serif;font-size:12px;line-height:17.1429px;background-color:transparent"><tbody><tr><td width="50"><img src="https://duo.com/assets/img/email/duo-logo-email-signature.gif" width="50" height="50" style="border:0px;vertical-align:middle;display:block"></td><td width="10"><img src="https://duo.com/assets/img/email/spacer.gif" width="10" height="50" style="border:0px;vertical-align:middle;display:block"></td><td valign="middle"><div style="margin:0px;font-family:Helvetica,sans-serif;display:inline"><strong style="display:inline">Xander Desai</strong> <div style="margin:0px;display:inline"><span style="color:rgb(153,153,153)">/</span> <span>Software Engineer II</span></div> <div style="margin:0px;display:inline"><br><a href="mailto:xdesai@duo.com" style="color:rgb(99,178,70);text-decoration:none" target="_blank">xdesai@duo.com</a></div> <div style="margin:0px;display:inline"><br><span>(734) 660-5055</span> <span>Cell Phone</span></div> <div style="margin:0px;display:inline"><br style="display:inline"><a href="https://duo.com/" style="color:rgb(99,178,70);text-decoration:none" target="_blank">Duo.com</a></div></div></td><td><img src="https://duo.com/assets/img/email/spacer.gif" width="1" height="50" style="border:0px;vertical-align:middle;display:block"></td></tr><tr><td colspan="4"><div style="margin:0px;display:inline"><br><span style="display:inline">----------<br>The Most Loved Company in Security</span></div></td></tr></tbody></table></div></div></div></div>
</div>