On September 7th, the owner of the Colorbox library unceremoniously archived the project on GitHub.

In doing so, a critical issue was closed without a merge: jQuery 4 support (requirement for Drupal 11 support).

To maintain compatibility with evolving versions of jQuery, we (Turbojet) are forking the Colorbox repo. The forked repo is at https://github.com/TurbojetTechnologies/colorbox.

Remaining tasks:

Issue fork colorbox-3549797

Command icon Show commands

Start within a Git clone of the project using the version control instructions.

Or, if you do not have SSH keys set up on git.drupalcode.org:

Comments

kmonty created an issue. See original summary.

paulmckibben’s picture

Title: Future of Colorbox Module Now the Colorbox Library Has Been End-of-Lifed » Colorbox Library Has Been End-of-Lifed: Fork it and Update it for jQuery 4 Compatibility
Category: Plan » Task
Issue summary: View changes
Priority: Normal » Major

@kmonty, thanks for sharing that the original Colorbox repository was archived on Github.

Given that there are many Drupal sites dependent on colorbox, it makes sense to fork the Github repository to ensure ongoing compatibility with jQuery.

I've changed the category of this issue to a Task. My company has cloned the colorbox repo at https://github.com/TurbojetTechnologies/colorbox with the intent to maintain compatibility with jQuery and other minimal maintenance tasks, maintaining parity with its current feature set (I don't anticipate we'll have time/bandwidth to implement new features).

We have a few more steps to complete, including merging the PR at https://github.com/jackmoore/colorbox/pull/908, updating instructions on the project page, and updating any references to the original library in the code to the forked library.

I hope to have time to do all this over the next week or so.

paulmckibben’s picture

Assigned: Unassigned » paulmckibben
kmonty’s picture

While updating the library, it might be worth looking at the other closed PRs and evaluating them for inclusion.

For example, this alleged XSS vulnerability has a PR: https://github.com/jackmoore/colorbox/pull/910 (Note: this security report is pretty thin, so it's unclear to me how real this is or not)

nickdickinsonwilde’s picture

Hey @paulmckibben,
What's the status of this. I see commits in the github repo https://github.com/TurbojetTechnologies/colorbox/commits/feature/jquery-... in october but not a release.

paulmckibben’s picture

@nickdickinsonwilde, thanks for the bump. I'll try to find time this week to issue a release in the github repo and update the installation instructions.

FWIW, the current version of the colorbox module has a workaround for the isFunction method (see https://git.drupalcode.org/project/colorbox/-/blob/2.1.x/js/colorbox.js?...), and I believe Drupal core has a workaround for bind and unbind, so colorbox should still work in Drupal 11 (it worked last time I checked), but I recognize the importance of having a version of the library that is compatible with jQuery 4.

Please correct me if there's a use case where the current version breaks. Thanks!

  • paulmckibben committed b8c71d25 on 2.2.x
    Resolve #3549797 "Colorbox library has been end-of-lifed"
    
paulmckibben’s picture

Status: Active » Fixed

Release 2.2.0 now supports the Turbojet fork of the Colorbox library. It will not work with the old library.
The 2.1.x branch remains supported for now, which still works with the old library.

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.

joegl’s picture

This should have been in a major release, not a minor release.

dasginganinja’s picture

^^^ This is a breaking change and should have been a major release. I'll echo the above statement and hope that future breaking changes will be included only in majors. Please and thank you.

paulmckibben’s picture

Message received. Sorry for the trouble. Unfortunately, what's done is done, and if there is a next time, I will know better.

Sincerely,
Your time-strapped volunteer Colorbox maintainer who has the best intentions but sometimes gets it wrong.

dasginganinja’s picture

Hi Paul. We are greatly appreciative of your efforts for this project. :) Thank you.

joegl’s picture

Same as what @dasginganinja said. Happens to all of us, no worries

ericvl’s picture

Hello,
I'm thinking loud now but a solution for the situation now is to tag the 2.1.4 version with a new releasetag 2.2.1 and make a new releasetag 3.0.0 on the same version of the 2.2.0 tag.
So, if one try to update his 2.1.4 version it will update to the new 2.2.1 version without the new jQuery compatibility. A null operation.
To get the new compatibility, one has to do a new "composer require" with the new ^3 version.
Just an idea
Thank uou for all your work.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.

bmunslow’s picture

In case someone else needs to add the library by means of composer, this is how to do it:

1. Add this to your composer.json file in the "repositories" section:

    "repositories": {
        "drupal": {
            "type": "composer",
            "url": "https://packages.drupal.org/8"
        },
        "colorbox": {
            "type": "package",
            "package": {
                "name": "turbojettechnologies/colorbox",
                "version": "1.7.0",
                "type": "drupal-library",
                "dist": {
                    "url": "https://github.com/TurbojetTechnologies/colorbox/archive/refs/tags/1.7.0.zip",
                    "type": "zip"
                }
            }
        }
    },

2. Require the package:

composer require 'turbojettechnologies/colorbox:^1.7'

miksha’s picture

I also came to the same conclusion to use composer as in comment #18. But what I believe is wrong in instructions on https://www.drupal.org/project/colorbox/releases/2.2.0 is that by using drush command in example a deploy script, and if at the same time this library fork gets changed, we could end up with different library versions per deploy environments and also overall with a forked library version that is not in sync with our drupal colorbox module version.
I believe release information and REQUIRMENTS section of the README.md should be updated not to just suggest update with:

You can install the Colorbox library using drush: drush colorbox:plugin

Or drush command should get library per tag e.g. https://github.com/TurbojetTechnologies/colorbox/archive/refs/tags/1.7.0...

johnpicozzi’s picture

I just upgraded to Drupal 11 and noticed my colorbox elements didn't open when clicked. That lead me to this issue https://www.drupal.org/project/colorbox/issues/3529726 which lead me here.

I did add the library via the drush command, however it didn't seem to resolve the issue. Adding the library via composer as suggested in #18 above worked for me. However I had to update the code as follows.

"repositories": [
        {
            "type": "composer",
            "url": "https://packages.drupal.org/8"
        },
        {
            "type": "path",
            "url": "upstream-configuration"
        },
        {
            "type": "package",
            "package": {
                "name": "turbojettechnologies/colorbox",
                "version": "1.7.0",
                "type": "drupal-library",
                "dist": {
                    "url": "https://github.com/TurbojetTechnologies/colorbox/archive/refs/tags/1.7.0.zip",
                    "type": "zip"
                }
            }
        }
    ],

Hopefully this helps someone in the future. Thanks All!

boulaffasae’s picture

Assigned: paulmckibben » Unassigned

A big thank to @paulmckibben, and to everyone at Turbojet for maintaining the Colorbox fork and making the jQuery 4 transition much smoother.