On Monday November 28th, we’ll be releasing version 3.0.0 of the drag-and-drop-v2 xblock. This release will contain a High level security fix as determined using CVSS.
We’re working to figure out the exact time of the release and will post that as soon as we have it.
I’m sure you know this already Feanil but I’ll mention it anyway: Nutmeg currently uses xblock-drag-and-drop-v2==v2.3.5, which is much older than the current v2.6.0, so if this security issue affects Nutmeg we’ll need to make sure that v3.0.0 is compatible with the named release. I have no idea whether v2.6.0 is compatible with Nutmeg.
Will there be separate patches released for nutmeg and olive or are we going to have to have to bump the xblock all the way to 3.0.0 in nutmeg and olive branches as well?