Actions

Difference between revisions of "Developer Area/Plugins/Third party"

From Mahara Wiki

< Developer Area‎ | Plugins
m
 
(187 intermediate revisions by 4 users not shown)
Line 1: Line 1:
A list of the third party plugins within Mahara.
+
A list of the third-party plugins within Mahara.
  
A helpful way to update this list is to go:
+
=== Composer commands ===
   find ./htdocs -type f -iname "README.Mahara" -exec grep 'Version' -B1 {} \; -print
+
For available versions, e.g.  <code>composer show phpro/grumphp-shim 1.14.* --all</code>
on the current codebase.
+
 
 +
For our composer dependencies:  <code>composer show  --tree</code>
 +
 
 +
For checking the dependencies of a library version, e.g. <code>composer show elasticsearch/elasticsearch 7.17.* --tree</code>
 +
 
 +
Check if there are any outdated libraries (according to the [[SemVer Info|version syntax]] in <code>composer.json</code>)  <code>composer outdated</code>
 +
 
 +
=== Checking the <code>.Mahara</code> files ===
 +
To check the versions in the <code>.Mahara</code> files, a helpful way to update this list is to go:
 +
   <code>find ./htdocs -type f -iname "README.Mahara" -exec grep 'Version' -B1 {} \; -print</code>
 +
... on the current codebase.
 +
 
 +
=== Syncing the list in 'Country' dropdowns ===
 +
To keep in sync is the country names we use for 'Country' dropdowns. To check what the current state of play is
 +
<code>perl -MLocale::Country -le 'print join("\n", sort map { country2code($_) . " => " . country2code($_, LOCALE_CODE_ALPHA_3) . ", // " . $_ } all_country_names())'</code>
 +
and check the results against <code>htdocs/lib/country.php</code> and <code>htdocs/lang/en.utf8/mahara.php</code> files
  
Note: another thing to keep in sync is the country names we use for 'Country' dropdowns. To check what the current state of play is
 
  perl -MLocale::Country -le 'print join("\n", sort map { country2code($_) . " => " . country2code($_, LOCALE_CODE_ALPHA_3) . ", // " . $_ } all_country_names())'
 
and check the results against htdocs/lib/country.php and htdocs/lang/en.utf8/mahara.php files
 
 
For any confusion you can also check against https://www.iso.org
 
For any confusion you can also check against https://www.iso.org
  
Indicating what version they are on in Mahara and what they currently are on at time of publishing 09 Jan 2019:
+
== Third-party libraries (PHP and JS) ==
 +
 
 +
=== Legend ===
 +
*'''Mahara version''' = the <code>README.Mahara</code> file for the library | [https://nodejs.dev/learn/semantic-versioning-using-npm SemVer Info] - explaining the symbols in the Mahara version column
 +
*'''Latest version''' = the most recent available version
 +
*'''Update type''' = what upgrades are available for this plugin, i.e. major, minor, patch, or security?
 +
*'''Support''' = Is there a community supporting this library? When was the last release year if not in active support
 +
**Active: There is ongoing work being put into the library
 +
**Inactive: Maintained but not actively making releases
 +
**Archived: Not being maintained
 +
**Deprecated (officially): All maintainers have left, and site may not exist in extreme cases.
 +
*'''License''' = software license for the library
 +
*'''Notes''' = extra information, e.g. resources, notes, and new
 +
*'''Composer''' = check if the library is managed by Composer
 +
*'''NPM''' = check if the library is managed by NPM
 +
'''PHP versions in support''' https://www.php.net/supported-versions.php<nowiki/>⁣ – 14 LTS - Ends security support in 30 Apr 2023, go to 16 LTS soon
 +
 
 +
💡 A new idea is being proposed to better handle customisations on updating third party libraries lives here → https://reviews.mahara.org/c/mahara/+/13780
 +
 
 +
=== PHP libraries (excluding external) ===
 +
https://eusonlito.github.io/php-changes-cheatsheet/deprecated.html
 +
 
 +
Libraries are managed by Composer. See <code>composer.json</code>
 +
 
 +
Run <code>composer show</code> to get a quick summary of library versions managed by Composer.
  
Current versions marked in <span style="color:red">Red</span> indicate the plugin needs updating/upgrading.
+
Run <code>composer outdated</code> to get a list of outdated libraries.
  
{| class=wikitable
+
🟡 Libraries yet to be moved to Composer: SimpleSAMLPHP - currently lives in <code>htdocs/auth/saml/extlib</code> and the version is managed in Makefile by curl.
 +
{| class="wikitable sortable" style="vertical-align:middle;"
 +
|- style="font-weight:bold; text-align:center;"
 +
!'''Name'''
 +
!'''Mahara <br />version'''
 +
!'''Update type'''
 +
!'''Support'''
 +
!'''License'''
 +
!'''URL/Notes'''
 +
!'''Composer'''
 
|-
 
|-
! Name !! Readme file !! URL !! License !! Current version !! Latest version !! Latest branch version !! Requirements of latest version !! Note !! Estimated upgrade time !! Notifications
+
| style="font-weight:bold;" |'''ADODB'''
 +
|5.22.6
 +
|Up to date
 +
|Active
 +
|BSD 3-Clause<br />LGPL
 +
|[https://adodb.org/dokuwiki/doku.php Official site]<nowiki> | </nowiki>[https://github.com/ADOdb/ADOdb GitHub]<nowiki> | </nowiki>[https://twitter.com/ADOdb_announce Twitter]<br />Wish-list: [https://bugs.launchpad.net/mahara/+bug/1945264 extract $SESSION]
 +
|✅
 
|-
 
|-
| ADODB || ./htdocs/lib/adodb/README.mahara || http://adodb.org/ || Dual-licensed under the BSD and Lesser GPL license, with the BSD License having priority. || 5.20.18 || 5.20.20 ||  || || The latest version uses PHP 8. The latest RC 5.21 focuses on PHP 8 compatibility https://github.com/ADOdb/ADOdb/milestone/2.1 || ADOB release all news on current releases + important bug fixes on https://twitter.com/ADOdb_announce first.
+
| style="font-weight:bold;" |'''CSS Tidy'''
 +
|2.1.0
 +
|Up to date
 +
|Active
 +
|LGPL
 +
|[https://github.com/Cerdic/CSSTidy GitHub]
 +
|
 
|-
 
|-
| Bootstrap || ./htdocs/lib/bootstrap/README.Mahara || https://getbootstrap.com/  || MIT License || 4.3.1 || 4.6.0 || Dependencies: Updated to jQuery v3.5.1, Jekyll v4, and dropped Node.js < 10 for development ||  || There have been minor point releases since we upgraded and v5 rolling out soon|| Investigation needed (Liam?) || Bootstrap has an RSS feed: https://blog.getbootstrap.com/feed.xml <br/>and a twitter account: https://twitter.com/getbootstrap
+
| style="font-weight:bold;" |'''Elasticsearch PHP'''
 +
| style="color:#333;" |7.17.2
 +
|Major, 8.10.0
 +
|Active
 +
|Apache v2.0  LGPL v2.1
 +
|[https://github.com/elastic/elasticsearch-php GitHub]<nowiki> | </nowiki>[https://github.com/elastic/elasticsearch-php/blob/master/CHANGELOG.md Changelog]
 +
Move to OpenSearch
 +
 
 +
|✅
 
|-
 
|-
| Bootstrap Datetimepicker || ./htdocs/js/bootstrap-datetimepicker/README.mahara || https://eonasdan.github.io/bootstrap-datetimepicker/ || MIT License || 4.17.47 || 4.17.47 ||  ||  || runs using bootstrap and moment.js  Current at July 2020 || n/a || n/a
+
| style="font-weight:bold;" |'''HTML Purifier'''
 +
|4.16.0
 +
|Up to date
 +
|2022
 +
|LGPL v2.1+
 +
|[http://www.htmlpurifier.org/ HTML Purifier]<nowiki> | </nowiki>[https://github.com/ezyang/htmlpurifier/ GitHub]
 +
|
 
|-
 
|-
| Chart.js || ./htdocs/js/chartjs/README.mahara || http://www.chartjs.org  || MIT License || 2.9.3 || 2.9.4 ||  || - ||  || n/a || n/a
+
| style="font-weight:bold;" |'''PHPMailer'''
 +
|6.8.1
 +
|Up to date
 +
|Active
 +
|LGPL
 +
|[https://github.com/PHPMailer/PHPMailer GitHub]
 +
|
 
|-
 
|-
| Clipboard js || ./htdocs/js/clipboard/README.Mahara || https://clipboardjs.com/ || MIT License || 2.0.6 || 2.0.6 ||  ||  || Up to date as of 2021-02-18 || looks like a bug fix, looks like one of the smaller upgrades  || n/a
+
| style="font-weight:bold;" |'''ReCaptcha'''
 +
|1.2.4
 +
|Minor, 1.3.0
 +
|Active
 +
|BSD-3
 +
|[https://github.com/google/recaptcha GitHub]
 +
|
 
|-
 
|-
| Cookie consent || ./htdocs/js/cookieconsent/README.mahara || https://www.osano.com/cookieconsent || MIT License || 3.1.1 || 3.1.1 ||  ||  || Current at July 2020 <br> NB: Has changed ownership, but there is still an OS version, which we are using || n/a || n/a
+
| style="font-weight:bold;" |'''simplesamlphp'''
 +
|2.0.4
 +
|Minor, 2.0.6
 +
|Active
 +
|GPL 2.1
 +
|[https://github.com/simplesamlphp/simplesamlphp GitHub]
 +
Optional library - called in Makefile
 +
|
 +
|}
 +
 
 +
=== JavaScript and jQuery libraries ===
 +
🟡 '''Check that our Node version is still in support''' https://endoflife.date/nodejs  node| https://nodejs.org/en/download/releases/ ➡ Update the <code>.nvmrc</code> file with the supported version.
 +
 
 +
Run <code>npm list</code> to get a quick list of the versions and libraries managed by NPM
 +
 
 +
Goal: to move libraries to be managed by NPM
 +
 
 +
==== NPM-managed JS libraries ====
 +
{| class="wikitable sortable" style="vertical-align:middle;"
 +
|- style="font-weight:bold; text-align:center;"
 +
!'''Name'''
 +
!'''Mahara <br />version'''
 +
!'''Update type'''
 +
!'''Support'''
 +
!'''License'''
 +
!'''Notes'''
 
|-
 
|-
| CSS Tidy || ./htdocs/lib/csstidy/README.Mahara || https://github.com/Cerdic/CSSTidy || LGPL || 1.7.1 || 1.7.1 ||   || PHP 5.4+ || || n/a || n/a
+
| style="font-weight:bold;" |'''yargs'''
 
+
|5.0.2
 +
|Minor, 5.3.2
 +
|Active
 +
|MIT
 +
|
 
|-
 
|-
| Dragon-drop || ./htdocs/js/dragondrop/README.mahara || https://github.com/schne324/dragon-drop || MIT License || 3.2.1 || 3.2.1 ||  ||  || Up to date at July 2020 <br> last updated August 2019 || n/a  || n/a
+
| style="font-weight:bold;" |'''Chart.js'''
 +
|3.9.1
 +
|Major, 4.4.0
 +
|Active
 +
|MIT
 +
|[https://www.chartjs.org/docs/latest/migration/v4-migration.html Migration to v4]
 
|-
 
|-
| Dropzone || ./htdocs/js/dropzone/README.mahara || https://github.com/enyo/dropzone  || MIT License || <span style="color:red">5.5.0</span> || 5.7.0 || ||  || Released Mar 10 <br> last updated July 2020 || we have no customisations, should be straight forward || n/a
+
| style="font-weight:bold;" |'''Clipboard js'''
 +
|2.0.11
 +
|Up to date
 +
|Active
 +
|MIT
 +
|version # is tagged
 
|-
 
|-
| Dwoo || ./htdocs/lib/dwoo/README.Mahara || <del>http://dwoo.org/, </del> https://github.com/dwoo-project/dwoo || GNU Lesser General Public License v3.0 || 1.3.7 || 1.3.7 || || PHP 5.3+ || Current at July 2020. Last updated July 2018 || n/a <br>NB: This library is no longer maintained || n/a <br>We will soon look at replacing this library
+
| style="font-weight:bold;" |'''Dragon-drop'''
+
|3.6.1
 +
|Up to date
 +
|2020
 +
|MIT
 +
|
 
|-
 
|-
| Elastic Search || ./htdocs/lib/elasticsearch/README.Mahara || https://github.com/elastic/elasticsearch-php || Apache v2.0 <br>LGPL v2.1 || <span style="color:red">6.1.0</span> || 7.8.0 ||  || PHP 7.1 <br>Native JSON 1.3.7 or higher || https://github.com/elastic/elasticsearch-php/blob/master/CHANGELOG.md <br> Patch in review to upgrade to 7.5, (Bug 1840101: update elasticsearch-php to 7.5) which currently works with ES server 6.8, but not 7.Note that our code needs to be upgraded so we can connect to ES server 7.6, which is a separate issue. || Investigation in process to upgrade our code.<br>---<br> Elastic Search PHP 7.8.0 is compatible with Elastic Search 7.8.0 || signed up to mailing list
+
| style="font-weight:bold;" |'''Dropzone'''
 +
|5.9.3
 +
|Patch, 5.9.3
 +
|2021
 +
|MIT
 +
|
 
|-
 
|-
| fancybox3 || ./htdocs/js/fancybox/README.Mahara || https://fancyapps.com/fancybox/3/ || GPL 3.0 || 3.5.6 || 3.5.7 ||   ||  || no significant changes || n/a || Make their announcements via twitter <br>https://twitter.com/thefancyapps
+
| style="font-weight:bold;" |'''jQuery'''
 +
|3.7.1
 +
|Up to date
 +
|Active
 +
|MIT
 +
|[https://forum.jquery.com/ Forum]
 
|-
 
|-
| gridstack || ./htdocs/js/gridstack/README.Mahara || https://github.com/gridstack/gridstack.js || MIT License || <span style="color:red">0.4.0</span> || 1.1.2 ||  ||  || A lot of activity in the past few months - looks to be significant structural changes, including removing jquery. || Investigation needed, but looks like a large change (Cecilia?) Change log: https://github.com/gridstack/gridstack.js/blob/develop/doc/CHANGES.md || questions can be posted in their slack channel <br>[https://join.slack.com/t/gridstackjs/shared_invite/enQtODE1NzkxMTUzNTIzLTA1NTEzZGE2NzliMGY5M2IwN2UzNWUzYmY2YTA0OTFlMTlmMDA3MTg3MGViZTRhZjM0N2QyODMyMjc1NzY4ZWQ slack channel]
+
| style="font-weight:bold;" |'''jQuery UI'''
 +
|1.13.2
 +
|Up to date
 +
|Active
 +
|MIT
 +
|
 
|-
 
|-
| HTML Purifier || ./htdocs/lib/htmlpurifier/README.Mahara || http://www.htmlpurifier.org/ || LGPL v2.1+ ||4.13.0 || 4.13.0 ||  || PHP >5.3 || New version supports PHP 7.4 || || updates via the 'NEWS' section on github README <br>https://github.com/ezyang/htmlpurifier/blob/v4.13.0/NEWS
+
| style="font-weight:bold;" |'''JS Color'''
 +
|2.5.1
 +
|Up to date
 +
|Inactive,2022
 +
|GPL 3
 +
|
 
|-
 
|-
| Javascript templates || ./htdocs/js/javascript-templates/README.Mahara || https://github.com/blueimp/JavaScript-Templates || MIT License || 3.11.0 || 3.18.0 ||  || node.js|| They made some formatting changes, but no real changes. We don't need to upgrade || n/a || n/a
+
| style="font-weight:bold;" |'''Marked'''
 +
|4.3.0
 +
|Minor, 4.3.0
 +
Major 9.1.0
 +
|Active
 +
|MIT
 +
|
 
|-
 
|-
| jQuery || ./htdocs/js/jquery/README.Mahara || http://jquery.com/ || MIT License || 3.5.1 || 3.5.1 || ||  ||  || || Twitter: https://twitter.com/jquery <br> QA: https://forum.jquery.com/<br> IRC https://irc.jquery.org/
+
| style="font-weight:bold;" |'''Moment.js'''
 +
|2.29.4
 +
|Up to date
 +
|Active
 +
|MIT
 +
|[http://momentjs.com/ Moment JS] 🆕 [https://moment.github.io/luxon/#/ Luxon GitHub]
 
|-
 
|-
| jQuery mobile || ./htdocs/js/jquery/jquery-mobile/README.Mahara || http://jquerymobile.com || MIT License ||  1.5.0-alpha.1 || 1.5.0-rc1 || || || released Sept 2018, last updated  Jun 14, 2019 <br>touch.js last updated June 2016 (https://github.com/jquery/jquery-mobile/blob/master/js/events/touch.js) || No significant changes || QA: https://forum.jquery.com/jquery-mobile/
+
| style="font-weight:bold;" |'''Popper'''
 +
|2.11.8
 +
|Up to date
 +
|Active
 +
|MIT
 +
|[https://github.com/twbs/bootstrap/issues/31451 GitHub issue]<nowiki> | </nowiki>[https://dev.to/fezvrasta/smarter-tooltips-and&#x20;-popovers-with-popper-2-44bh tooltips]
 +
'''Floating UI'''
 
|-
 
|-
| jQuery UI || ./htdocs/js/jquery/jquery-ui/README.Mahara || http://jqueryui.com/ || MIT License || 1.12.1 || 1.12.1 ||  || jQuery 1.7+ || last updated July 2020 || n/a || jQuery Accessibility [https://groups.google.com/forum/#!forum/jquery-a11y jquery a11y forum] <br>
+
| style="font-weight:bold;" |'''Fontawesome'''
 +
|6.4.2
 +
|Up to date
 +
|Active
 +
|SIL OFL 1.1
 +
|[https://fontawesome.com/docs/web/setup/upgrade/ Upgrade steps]<nowiki> | </nowiki>[https://fontawesome.com/docs/changelog/ Changelog]
 
|-
 
|-
| jQuery UI plugin touch-punch || ./htdocs/js/jquery/jquery-ui/jquery-ui-touch-punch.min.js || http://touchpunch.furf.com/<br>https://github.com/furf/jquery-ui-touch-punch || MIT or GPL Version 2 licenses || 0.2.3 || 0.2.3 ||  || jquery, jquery-ui ||  is not currently being maintained  || n/a || n/a
+
| style="font-weight:bold;" |'''TinyMCE'''
 +
|5.10.7
 +
|Major, 6.7.0
 +
|Active
 +
|LGPL 2.1
 +
|[https://www.tiny.cloud/get-tiny/self-hosted Downloads]<nowiki> | </nowiki>[https://www.tiny.cloud/docs/changelog/ Changelog]
 +
📲 Test mobile
 
|-
 
|-
| JS Color || ./htdocs/js/jscolor/README.Mahara || http://jscolor.com/ || GPL 3 || 2.3.3 || 2.3.3 ||  ||  || bug fixes, extended features, performance tweaks || we have no customisations, hopefull straight forward upgrade, small? || n/a
+
| style="font-weight:bold;" |'''Video.js'''
 +
|7.21.5
 +
|Major, 8.5.2
 +
|Active
 +
|Apache License 2.0
 +
|[http://videojs.com/ Video JS]
 +
|}
 +
 
 +
==== Manually managed JS libraries ====
 +
{| class="wikitable sortable" style="vertical-align:middle;"
 +
|- style="font-weight:bold; text-align:center;"
 +
!'''Name'''
 +
!'''Mahara <br />version'''
 +
!'''Update type'''
 +
!'''Support'''
 +
!'''Location<br />'''<code><small>(./htdocs/...)</small></code>
 +
!'''License'''
 +
!'''Notes'''
 +
!'''NPM'''
 
|-
 
|-
| Json editor || ./htdocs/js/jsoneditor/README.Mahara || https://github.com/json-editor/json-editor || MIT License || 1.3.0 || 2.3.0 ||  || || There are a number of changes, not sure how it will affect us || Investigation needed || n/a
+
| style="font-weight:bold;" |'''Date time'''
 +
'''picker'''
 +
|4.17.47
 +
|Major 6.17.16
 +
|Active - v6
 +
|<small>.../js/bootstrap-datetimepicker/</small>
 +
|MIT
 +
|[https://getdatepicker.com/6/change-log.html Changelog]
 +
 
 +
Latest release: rewrite (beta)
 +
|
 
|-
 
|-
| jTLine || .htdocs/js/jTLine/README.Mahara || https://naadydev.github.io/jTLine/ || MIT License || 1.0 || 1.0 || || || Last updated Aug 2018. Our version is forked from the original || n/a || Twitter: https://twitter.com/naadydev
+
| style="font-weight:bold;" |'''Datatables'''
 +
|1.11.4
 +
|Minor
 +
|Active
 +
|<small>.../js/DataTables/</small>
 +
|MIT
 +
|[https://datatables.net/download/index Download]
 +
[https://cdn.datatables.net/ Release notes CDN]
 +
|❌ Need to use web builder
 
|-
 
|-
| Lodash || ./htdocs/js/lodash/README.Mahara || https://github.com/lodash/lodash || MIT License || <span style="color:red">4.17.15</span> || 4.17.16 ||  ||  || change log: https://github.com/lodash/lodash/wiki/Changelog <br>4.17.16 is latest release though change log shows from 14.17.15 to wip 4.17.19 || n/a?? Lodash was brought in with gridstack- gridstack v0.5.0 no longer have it as a requirement, if we upgrade gridstack we can probably let lodash go? || n/a - after we upgrade gridstack Lodash will be gone
+
| style="font-weight:bold;" |'''Gridstack'''
 +
|4.4.1
 +
|Major
 +
|Active
 +
|<small>.../js/gridstack/</small>
 +
|MIT
 +
|[Demos](<nowiki>https://gridstackjs.com/demo/</nowiki>)
 +
 
 +
 
 +
https://github.com/gridstack/gridstack.js/tree/master/doc
 +
|🚧
 
|-
 
|-
| Marked || ./htdocs/js/marked/README.Mahara || https://github.com/markedjs/marked || MIT License || <span style="color:red">0.7.0</span> || 1.1.1 ||  ||  || No security updates || What we use is a min.js file, so it's hard to diff. Probably small effort to upgrade, but allow for medium due to unknown || n/a
+
| style="font-weight:bold;" |'''Json editor'''
 +
|2.6.1
 +
|Minor
 +
|Active
 +
|<small>.../js/jsoneditor/</small>
 +
|MIT
 +
|[https://github.com/json-editor/json-editor/blob/master/CHANGELOG.md Changelog]
 +
|🚧
 
|-
 
|-
| Masonry || ./htdocs/js/masonry/README.Mahara || https://masonry.desandro.com/ || MIT License || 4.2.2 || 4.2.2 ||  ||  || Current at July 2020. Last updated Jul 2018 || n/a || n/a
+
| style="font-weight:bold;" |'''PDFjs'''
 +
|3.10.111
 +
|Minor 🚧
 +
|Active
 +
|<small>.../artefact/file/blocktype/pdf/js/pdfjs/</small>
 +
|Apache License 2
 +
|[http://mozilla.github.io/pdf.js/getting_started/#download Getting started]
 +
The Firefox dist version different to NPM package
 +
|
 +
|}
 +
 
 +
=== Forked/stale/deprecated libraries ===
 +
{| class="wikitable sortable mw-collapsible mw-collapsed" style="vertical-align:middle;"
 +
|- style="font-weight:bold; text-align:center;"
 +
!'''Name'''
 +
!'''Mahara <br />version'''
 +
!'''Latest<br />version'''
 +
!'''Support'''
 +
!'''Location<br />'''<code><small>(./htdocs/...)</small></code>
 +
!'''License'''
 +
!'''URL'''
 +
!'''Next action'''
 
|-
 
|-
| Mobile detect || ./htdocs/lib/mobile_detect/README.Mahara || http://mobiledetect.net/ || MIT License || <span style="color:red">2.8.33</span> || 2.8.34 ||   ||  || Supported devices have been updated || Updating effort looks small || n/a
+
| style="font-weight:bold;" |'''Dwoo'''
 +
|1.3.7
 +
|1.3.7
 +
|'''Archived, 2020'''
 +
|<small>.../lib/dwoo/</small>
 +
|LGPL
 +
|[http://dwoo.org/ Dead site?]
 +
[https://github.com/dwoo-project/dwoo GitHub]
 +
|
 
|-
 
|-
| Moment.js || ./htdocs/js/momentjs/README.Mahara || http://momentjs.com/ || MIT License || <span style="color:red">2.24.0</span> || 2.27.0 || ||  || used in conjunction with the bootstrap datetimepicker. || 2 releases have come out, looks like bug fixes <br>change log: https://gist.github.com/marwahaha <br> probably a small upgrade effort || n/a
+
| style="font-weight:bold;" |'''Javascript <br />templates'''
 +
|3.20.0
 +
|3.20.0
 +
|'''Archived, 2021'''
 +
|<small>.../js/javascript-templates/</small>
 +
|MIT
 +
|[https://github.com/blueimp/JavaScript-Templates GitHub]
 +
|
 
|-
 
|-
| Oauth PHP || ./htdocs/webservice/libs/oauth-php/README.Mahara || http://code.google.com/p/oauth-php/ || MIT License || 175 || 175 ||  ||  || This package is not maintained and was last updated in 2010 || We should replace with an oauth2 php library https://oauth.net/code/php/ and / or checkout what Moodle do || n/a
+
| style="font-weight:bold;" |'''jQuery mobile'''
 +
|1.5.0-alpha.1
 +
|1.5.0-rc1
 +
|'''Deprecated'''
 +
|<small>.../js/jquery/jquery-mobile/</small>
 +
|MIT
 +
|[http://jquerymobile.com Website] <br /><small>🚨 ''"transition(ed) ...''</small> <small>''under the jQuery project umbrella, jQuery UI"''</small>
 +
|Remove and test
 
|-
 
|-
| PDFjs || ./htdocs/artefact/file/blocktype/pdf/js/pdfjs/README.Mahara || http://mozilla.github.io/pdf.js/getting_started/#download || Apache License 2 || <span style="color:red">2.2.228</span> || 2.4.456 ||  ||  || change log:https://github.com/mozilla/pdf.js/releases/tag/v2.4.456 || Medium to large upgrade, depending on if structure changes. Investigation needed || n/a
+
| style="font-weight:bold;" |'''jQuery UI plugin <br />touch-punch'''
 +
|0.2.3
 +
|0.2.3
 +
|'''Deprecated'''
 +
|<small>.../js/jquery/jquery-ui/<br />jquery-ui-touch-punch.min.js</small>
 +
|MIT or GPL <br />Version 2
 +
|[https://github.com/furf/jquery-ui-touch-punch GitHub]
 +
 
 +
<small>🚨 external to JQuery UI</small>
 +
|[https://github.com/RWAP/jquery-ui-touch-punch Use a fork?]
 
|-
 
|-
| PHPMailer || ./htdocs/lib/phpmailer/README.Mahara || https://github.com/PHPMailer/PHPMailer || LGPL || 6.0.6 || 6.1.4 ||  ||  || Changes include compatibility fixes for PHP7.4 No security fixes || In progress <-- is there a patch for this? The latest version is now 6.1.7 (maintenance release) || n/a
+
| style="font-weight:bold;" |'''jTLine'''
 +
|1.0
 +
|1.0
 +
|'''Inactive, 2018'''
 +
|<small>.../js/jTLine/</small>
 +
|MIT
 +
|[https://naadydev.github.io/jTLine/ GitHub]
 +
[https://twitter.com/naadydev Twitter]
 +
 
 +
[https://codyhouse.co/gem/horizontal-timeline Ref]
 +
|
 
|-
 
|-
| Popper || ./htdocs/lib/popper/README.Mahara || https://popper.js.org/ || MIT License || 1.16.0 || 2.4.4 || || || Very active project with a lot of releases. || Used by Bootstrap. When Bootstrap updates to use popper V2x we will be able to upgrade popper.<br>https://github.com/twbs/bootstrap/pull/31178 || n/a
+
| style="font-weight:bold;" |'''Masonry'''
 +
|4.2.2
 +
|4.2.2
 +
|'''Inactive, 2018'''
 +
|<small>.../js/masonry/</small>
 +
|MIT
 +
|[https://masonry.desandro.com/ Masonry]
 +
[https://github.com/desandro/masonry GitHub]
 +
|
 
|-
 
|-
| ReCaptcha || ./htdocs/lib/recaptcha/README.Mahara || https://github.com/google/recaptcha || BSD-3 || 1.2.1 || 1.2.4 ||   || 5.5+ || Changes are to documentation, not code, so no need to update || n/a || n/a
+
| style="font-weight:bold;" |'''TinyMCE<br />Mathslate'''
 +
|1.1
 +
|1.1
 +
|'''Forked, 2015'''
 +
|<small>.../js/tinymce/plugins/mathslate/</small>
 +
|GPL 3
 +
|<small>Our version is [[GitHub|forked]].<br />to work with Tinymce 5</small>
 +
|
 
|-
 
|-
| Select2 || ./htdocs/js/select2/README.Mahara || https://select2.org/ || MIT License || 4.0.9 || 4.0.13 ||  ||  || Bug fixes and improvements, no major changes or security fixes || At least medium effort to upgrade, as there are several changes in Mahara and quite a bit of testing || n/a
+
| style="font-weight:bold;" |'''Oauth PHP'''
 +
|175
 +
|175
 +
|'''Archived, 2010'''
 +
|<small>.../webservice/libs/oauth-php/</small>
 +
|MIT
 +
|[https://code.google.com/archive/p/oauth-php/ Code]
 +
|<small>Replace with an</small> <small>[https://oauth.net/code/php oauth2 php library] see what Moodle does (old comment)</small>
 
|-
 
|-
| simplesamlphp || /htdocs/auth/saml/extlib/simplesamlphp/README.md || https://github.com/simplesamlphp/simplesamlphp || GPL 2.1 ||1.18.7 || 1.18.8 ||  || || || || We have joined the mailing list<br>https://simplesamlphp.org/lists
+
| style="font-weight:bold;" |'''zxcvbn'''
 +
|4.4.2
 +
|4.4.2
 +
|'''Inactive, 2017'''
 +
|<small>.../js/zxcvbn/</small>
 +
|MIT
 +
|[https://github.com/dropbox/zxcvbn GitHub]
 +
|
 
|-
 
|-
| Skin fonts || /htdocs/lib/fonts/README.Mahara || http://www.fontsquirrel.com/fonts/Aurulent-Sans ,http://www.fontsquirrel.com/fonts/DejaVu-Sans, http://scripts.sil.org/cms/scripts/page.php?item_id=CharisSIL, http://sourceforge.net/projects/gs-fonts/ || Multiple licenses || n/a, 2.29, 5.000, 8.11 ||  ||  ||  || no changes || n/a || n/a
+
|'''Cookie consent'''
 +
|3.1.1
 +
|4.0
 +
|'''No open source updates'''
 +
|<small>.../js/cookieconsent/</small>
 +
|MIT
 +
|[https://www.osano.com/cookieconsent Download] [https://github.com/osano/cookieconsent GitHub]
 +
 
 +
<small>Open source version is not updated. 🚨</small>
 +
|
 
|-
 
|-
| System fonts || ./htdocs/theme/raw/fonts/README.Mahara, ./htdocs/theme/raw/sass/lib/font-awesome/README.Mahara || http://fontawesome.io, https://www.google.com/fonts/specimen/Open+Sans, https://www.google.com/fonts/specimen/Roboto+Slab || http://fontawesome.io/license, MIT License, Apache License, version 2.0 || 5.8.1, 1, 1, 1.9 || 5.14.0, 1, 1, 1.9  ||        ||  || changes to unicode for fontawesome https://github.com/FortAwesome/Font-Awesome/blob/master/UPGRADING.md || medium effort to upgrade due to needing to check for issues. || n/a
+
|'''Select2'''
 +
|4.0.13
 +
|4.0.13
 +
|'''Inactive, 2020'''
 +
|<small>.../js/select2/</small>
 +
|MIT
 +
|[https://select2.org/ Select2]<nowiki> | </nowiki>[https://github.com/select2/select2/releases Releases]
 +
RC 4.1
 +
|
 +
|}
  
 +
=== Fonts ===
 +
{| class="wikitable sortable" style="vertical-align:middle;"
 +
!'''Name'''
 +
!'''Mahara <br />version'''
 +
!'''Latest<br />version'''
 +
!'''Status'''
 +
!'''README location<br />'''<code>(./htdocs/...)</code>
 +
!'''License'''
 +
!'''URL/Notes'''
 
|-
 
|-
| TinyMCE || ./htdocs/js/tinymce/README.Mahara || https://www.tiny.cloud/|| LGPL || 5.0.13 || 5.5.1 (October 2020) ||  ||  || A number of bug fixes and improvements<br>https://www.tiny.cloud/docs/changelog/<br>Test on mobile when updating || probably only worth updating if we are affected by any of the bugs they are fixing. Need to investigate that and how long it would take. || Blog: https://www.tiny.cloud/blog/category/news-and-updates/
+
| style="font-weight:bold;" |'''Aurulent Sans <br />(font)'''
 +
|2007.05.04
 +
|2007.05.04
 +
|n/a
 +
|<small>.../lib/fonts/</small>
 +
|SIL OFL v1.10
 +
|[https://www.fontsquirrel.com/fonts/aurulent-sans Font Squirrel Aurulent Sans]
 
|-
 
|-
| TinyMCE - Mathslate || ./htdocs/js/tinymce/plugins/mathslate/README.Mahara || https://github.com/dthies/tinymce4-mathslate || GPL 3 || 1.1 || 1.1 ||  ||  || no changes<br>Our version is now forked to keep make it work with Tinymce 5 || n/a
+
| style="font-weight:bold;" |'''Deja Vu Sans <br />(font)'''
|| n/a
+
|2.37
 +
|2.37
 +
|n/a
 +
|<small>.../lib/fonts/</small>
 +
|DejaVu Fonts
 +
|[http://www.fontsquirrel.com/fonts/DejaVu-Sans Font Squirrel Deja Vu Sans]
 
|-
 
|-
| Video.js || ./htdocs/artefact/file/blocktype/internalmedia/videojs/README.Mahara || http://videojs.com/ || Apache License 2.0 || 7.6.5 || 7.8.4 ||  ||  || Some bug fixes. Looks mostly minor changes<br>https://github.com/videojs/video.js/releases || Needs investigation. Probably small to medium || we have signed up to their mailing list
+
| style="font-weight:bold;" |'''Open Sans <br />(font)'''
 +
|1.10
 +
|1.10
 +
|Unknown
 +
|<small>.../theme/raw/fonts/</small>
 +
|Apache License
 +
|[https://www.google.com/fonts/specimen/Open+Sans Google Fonts Open Sans]
 
|-
 
|-
| zxcvbn || ./htdocs/js/zxcvbn/README.Mahara || https://github.com/dropbox/zxcvbn || MIT License || 4.4.2 || 4.4.2 ||  ||  || Current at July 2020<br>Last updated Feb 2017 || Should we change to a maintained library, eg https://github.com/bjeavons/zxcvbn-php? Yes we should but is that one just a port of the js version or is it an updated / more robust system? || n/a
+
| style="font-weight:bold;" |'''Roboto Slab <br />(font)'''
 +
|1.100263
 +
|1.100263
 +
|Unknown
 +
|<small>.../theme/raw/fonts/</small>
 +
|MIT
 +
|[https://www.google.com/fonts/specimen/Roboto+Slab Google Fonts Roboto]
 +
|-
 +
|'''Charis SIL <br />(fonts)'''
 +
|6.001
 +
|6.001
 +
|Active
 +
|<small>.././lib/fonts/</small>
 +
|SIL OFL
 +
|[http://scripts.sil.org/cms/scripts/page.php?item_id=CharisSIL About font]<nowiki> | </nowiki>[https://software.sil.org/charis/download/ Download]
 
|}
 
|}
 +
 +
=== Composer.json dependencies ===
 +
'''Resources:''' https://git.mahara.org | <code>/mahara/mahara/-/blob/</code> | <code>mahara/external/composer.json</code>
 +
 +
'''Run''' <code>composer outdated</code> to check for updates.

Latest revision as of 16:18, 4 January 2024

A list of the third-party plugins within Mahara.

Composer commands

For available versions, e.g. composer show phpro/grumphp-shim 1.14.* --all

For our composer dependencies: composer show --tree

For checking the dependencies of a library version, e.g. composer show elasticsearch/elasticsearch 7.17.* --tree

Check if there are any outdated libraries (according to the version syntax in composer.json) composer outdated

Checking the .Mahara files

To check the versions in the .Mahara files, a helpful way to update this list is to go:

 find ./htdocs -type f -iname "README.Mahara" -exec grep 'Version' -B1 {} \; -print

... on the current codebase.

Syncing the list in 'Country' dropdowns

To keep in sync is the country names we use for 'Country' dropdowns. To check what the current state of play is

perl -MLocale::Country -le 'print join("\n", sort map { country2code($_) . " => " . country2code($_, LOCALE_CODE_ALPHA_3) . ", // " . $_ } all_country_names())'

and check the results against htdocs/lib/country.php and htdocs/lang/en.utf8/mahara.php files

For any confusion you can also check against https://www.iso.org

Third-party libraries (PHP and JS)

Legend

  • Mahara version = the README.Mahara file for the library | SemVer Info - explaining the symbols in the Mahara version column
  • Latest version = the most recent available version
  • Update type = what upgrades are available for this plugin, i.e. major, minor, patch, or security?
  • Support = Is there a community supporting this library? When was the last release year if not in active support
    • Active: There is ongoing work being put into the library
    • Inactive: Maintained but not actively making releases
    • Archived: Not being maintained
    • Deprecated (officially): All maintainers have left, and site may not exist in extreme cases.
  • License = software license for the library
  • Notes = extra information, e.g. resources, notes, and new
  • Composer = check if the library is managed by Composer
  • NPM = check if the library is managed by NPM

PHP versions in support https://www.php.net/supported-versions.php⁣ – 14 LTS - Ends security support in 30 Apr 2023, go to 16 LTS soon

💡 A new idea is being proposed to better handle customisations on updating third party libraries lives here → https://reviews.mahara.org/c/mahara/+/13780

PHP libraries (excluding external)

https://eusonlito.github.io/php-changes-cheatsheet/deprecated.html

Libraries are managed by Composer. See composer.json

Run composer show to get a quick summary of library versions managed by Composer.

Run composer outdated to get a list of outdated libraries.

🟡 Libraries yet to be moved to Composer: SimpleSAMLPHP - currently lives in htdocs/auth/saml/extlib and the version is managed in Makefile by curl.

Name Mahara
version
Update type Support License URL/Notes Composer
ADODB 5.22.6 Up to date Active BSD 3-Clause
LGPL
Official site | GitHub | Twitter
Wish-list: extract $SESSION
CSS Tidy 2.1.0 Up to date Active LGPL GitHub
Elasticsearch PHP 7.17.2 Major, 8.10.0 Active Apache v2.0 LGPL v2.1 GitHub | Changelog

Move to OpenSearch

HTML Purifier 4.16.0 Up to date 2022 LGPL v2.1+ HTML Purifier | GitHub
PHPMailer 6.8.1 Up to date Active LGPL GitHub
ReCaptcha 1.2.4 Minor, 1.3.0 Active BSD-3 GitHub
simplesamlphp 2.0.4 Minor, 2.0.6 Active GPL 2.1 GitHub

Optional library - called in Makefile

JavaScript and jQuery libraries

🟡 Check that our Node version is still in support https://endoflife.date/nodejs node| https://nodejs.org/en/download/releases/ ➡ Update the .nvmrc file with the supported version.

Run npm list to get a quick list of the versions and libraries managed by NPM

Goal: to move libraries to be managed by NPM

NPM-managed JS libraries

Name Mahara
version
Update type Support License Notes
yargs 5.0.2 Minor, 5.3.2 Active MIT
Chart.js 3.9.1 Major, 4.4.0 Active MIT Migration to v4
Clipboard js 2.0.11 Up to date Active MIT version # is tagged
Dragon-drop 3.6.1 Up to date 2020 MIT
Dropzone 5.9.3 Patch, 5.9.3 2021 MIT
jQuery 3.7.1 Up to date Active MIT Forum
jQuery UI 1.13.2 Up to date Active MIT
JS Color 2.5.1 Up to date Inactive,2022 GPL 3
Marked 4.3.0 Minor, 4.3.0

Major 9.1.0

Active MIT
Moment.js 2.29.4 Up to date Active MIT Moment JS 🆕 Luxon GitHub
Popper 2.11.8 Up to date Active MIT GitHub issue | tooltips

Floating UI

Fontawesome 6.4.2 Up to date Active SIL OFL 1.1 Upgrade steps | Changelog
TinyMCE 5.10.7 Major, 6.7.0 Active LGPL 2.1 Downloads | Changelog

📲 Test mobile

Video.js 7.21.5 Major, 8.5.2 Active Apache License 2.0 Video JS

Manually managed JS libraries

Name Mahara
version
Update type Support Location
(./htdocs/...)
License Notes NPM
Date time

picker

4.17.47 Major 6.17.16 Active - v6 .../js/bootstrap-datetimepicker/ MIT Changelog

Latest release: rewrite (beta)

Datatables 1.11.4 Minor Active .../js/DataTables/ MIT Download

Release notes CDN

❌ Need to use web builder
Gridstack 4.4.1 Major Active .../js/gridstack/ MIT [Demos](https://gridstackjs.com/demo/)


https://github.com/gridstack/gridstack.js/tree/master/doc

🚧
Json editor 2.6.1 Minor Active .../js/jsoneditor/ MIT Changelog 🚧
PDFjs 3.10.111 Minor 🚧 Active .../artefact/file/blocktype/pdf/js/pdfjs/ Apache License 2 Getting started

The Firefox dist version different to NPM package

Forked/stale/deprecated libraries

Name Mahara
version
Latest
version
Support Location
(./htdocs/...)
License URL Next action
Dwoo 1.3.7 1.3.7 Archived, 2020 .../lib/dwoo/ LGPL Dead site?

GitHub

Javascript
templates
3.20.0 3.20.0 Archived, 2021 .../js/javascript-templates/ MIT GitHub
jQuery mobile 1.5.0-alpha.1 1.5.0-rc1 Deprecated .../js/jquery/jquery-mobile/ MIT Website
🚨 "transition(ed) ... under the jQuery project umbrella, jQuery UI"
Remove and test
jQuery UI plugin
touch-punch
0.2.3 0.2.3 Deprecated .../js/jquery/jquery-ui/
jquery-ui-touch-punch.min.js
MIT or GPL
Version 2
GitHub

🚨 external to JQuery UI

Use a fork?
jTLine 1.0 1.0 Inactive, 2018 .../js/jTLine/ MIT GitHub

Twitter

Ref

Masonry 4.2.2 4.2.2 Inactive, 2018 .../js/masonry/ MIT Masonry

GitHub

TinyMCE
Mathslate
1.1 1.1 Forked, 2015 .../js/tinymce/plugins/mathslate/ GPL 3 Our version is forked.
to work with Tinymce 5
Oauth PHP 175 175 Archived, 2010 .../webservice/libs/oauth-php/ MIT Code Replace with an oauth2 php library see what Moodle does (old comment)
zxcvbn 4.4.2 4.4.2 Inactive, 2017 .../js/zxcvbn/ MIT GitHub
Cookie consent 3.1.1 4.0 No open source updates .../js/cookieconsent/ MIT Download GitHub

Open source version is not updated. 🚨

Select2 4.0.13 4.0.13 Inactive, 2020 .../js/select2/ MIT Select2 | Releases

RC 4.1

Fonts

Name Mahara
version
Latest
version
Status README location
(./htdocs/...)
License URL/Notes
Aurulent Sans
(font)
2007.05.04 2007.05.04 n/a .../lib/fonts/ SIL OFL v1.10 Font Squirrel Aurulent Sans
Deja Vu Sans
(font)
2.37 2.37 n/a .../lib/fonts/ DejaVu Fonts Font Squirrel Deja Vu Sans
Open Sans
(font)
1.10 1.10 Unknown .../theme/raw/fonts/ Apache License Google Fonts Open Sans
Roboto Slab
(font)
1.100263 1.100263 Unknown .../theme/raw/fonts/ MIT Google Fonts Roboto
Charis SIL
(fonts)
6.001 6.001 Active .././lib/fonts/ SIL OFL About font | Download

Composer.json dependencies

Resources: https://git.mahara.org | /mahara/mahara/-/blob/ | mahara/external/composer.json

Run composer outdated to check for updates.