Closed (fixed)
Project:
Colorbox
Version:
2.1.x-dev
Component:
Code
Priority:
Major
Category:
Task
Assigned:
Unassigned
Reporter:
Created:
1 Oct 2025 at 15:36 UTC
Updated:
12 Jul 2026 at 15:12 UTC
Jump to comment: Most recent
On September 7th, the owner of the Colorbox library unceremoniously archived the project on GitHub.
In doing so, a critical issue was closed without a merge: jQuery 4 support (requirement for Drupal 11 support).
To maintain compatibility with evolving versions of jQuery, we (Turbojet) are forking the Colorbox repo. The forked repo is at https://github.com/TurbojetTechnologies/colorbox.
Remaining tasks:
Start within a Git clone of the project using the version control instructions.
Or, if you do not have SSH keys set up on git.drupalcode.org:
Comments
Comment #2
paulmckibben@kmonty, thanks for sharing that the original Colorbox repository was archived on Github.
Given that there are many Drupal sites dependent on colorbox, it makes sense to fork the Github repository to ensure ongoing compatibility with jQuery.
I've changed the category of this issue to a Task. My company has cloned the colorbox repo at https://github.com/TurbojetTechnologies/colorbox with the intent to maintain compatibility with jQuery and other minimal maintenance tasks, maintaining parity with its current feature set (I don't anticipate we'll have time/bandwidth to implement new features).
We have a few more steps to complete, including merging the PR at https://github.com/jackmoore/colorbox/pull/908, updating instructions on the project page, and updating any references to the original library in the code to the forked library.
I hope to have time to do all this over the next week or so.
Comment #3
paulmckibbenComment #4
kmontyWhile updating the library, it might be worth looking at the other closed PRs and evaluating them for inclusion.
For example, this alleged XSS vulnerability has a PR: https://github.com/jackmoore/colorbox/pull/910 (Note: this security report is pretty thin, so it's unclear to me how real this is or not)
Comment #5
nickdickinsonwildeHey @paulmckibben,
What's the status of this. I see commits in the github repo https://github.com/TurbojetTechnologies/colorbox/commits/feature/jquery-... in october but not a release.
Comment #6
paulmckibben@nickdickinsonwilde, thanks for the bump. I'll try to find time this week to issue a release in the github repo and update the installation instructions.
FWIW, the current version of the colorbox module has a workaround for the isFunction method (see https://git.drupalcode.org/project/colorbox/-/blob/2.1.x/js/colorbox.js?...), and I believe Drupal core has a workaround for bind and unbind, so colorbox should still work in Drupal 11 (it worked last time I checked), but I recognize the importance of having a version of the library that is compatible with jQuery 4.
Please correct me if there's a use case where the current version breaks. Thanks!
Comment #9
paulmckibbenRelease 2.2.0 now supports the Turbojet fork of the Colorbox library. It will not work with the old library.
The 2.1.x branch remains supported for now, which still works with the old library.
Comment #11
joegl commentedThis should have been in a major release, not a minor release.
Comment #12
dasginganinja^^^ This is a breaking change and should have been a major release. I'll echo the above statement and hope that future breaking changes will be included only in majors. Please and thank you.
Comment #13
paulmckibbenMessage received. Sorry for the trouble. Unfortunately, what's done is done, and if there is a next time, I will know better.
Sincerely,
Your time-strapped volunteer Colorbox maintainer who has the best intentions but sometimes gets it wrong.
Comment #14
dasginganinjaHi Paul. We are greatly appreciative of your efforts for this project. :) Thank you.
Comment #15
joegl commentedSame as what @dasginganinja said. Happens to all of us, no worries
Comment #16
ericvlHello,
I'm thinking loud now but a solution for the situation now is to tag the 2.1.4 version with a new releasetag 2.2.1 and make a new releasetag 3.0.0 on the same version of the 2.2.0 tag.
So, if one try to update his 2.1.4 version it will update to the new 2.2.1 version without the new jQuery compatibility. A null operation.
To get the new compatibility, one has to do a new "composer require" with the new ^3 version.
Just an idea
Thank uou for all your work.
Comment #18
bmunslow commentedIn case someone else needs to add the library by means of composer, this is how to do it:
1. Add this to your composer.json file in the "repositories" section:
2. Require the package:
composer require 'turbojettechnologies/colorbox:^1.7'Comment #19
miksha commentedI also came to the same conclusion to use composer as in comment #18. But what I believe is wrong in instructions on https://www.drupal.org/project/colorbox/releases/2.2.0 is that by using drush command in example a deploy script, and if at the same time this library fork gets changed, we could end up with different library versions per deploy environments and also overall with a forked library version that is not in sync with our drupal colorbox module version.
I believe release information and REQUIRMENTS section of the README.md should be updated not to just suggest update with:
Or drush command should get library per tag e.g. https://github.com/TurbojetTechnologies/colorbox/archive/refs/tags/1.7.0...
Comment #20
johnpicozziI just upgraded to Drupal 11 and noticed my colorbox elements didn't open when clicked. That lead me to this issue https://www.drupal.org/project/colorbox/issues/3529726 which lead me here.
I did add the library via the drush command, however it didn't seem to resolve the issue. Adding the library via composer as suggested in #18 above worked for me. However I had to update the code as follows.
Hopefully this helps someone in the future. Thanks All!
Comment #21
boulaffasae commentedA big thank to @paulmckibben, and to everyone at Turbojet for maintaining the Colorbox fork and making the jQuery 4 transition much smoother.