Closed dependabot[bot] closed 3 years ago
@dependabot merge
2021年5月7日(金) 19:32 dependabot[bot] @.***>:
This automated pull request fixes a security vulnerability https://github.com/JXA-userland/JXA/security/dependabot/yarn.lock/handlebars/open (critical severity).
Learn more about Dependabot security updates https://docs.github.com/github/managing-security-vulnerabilities/configuring-dependabot-security-updates.
Bumps handlebars https://github.com/wycats/handlebars.js from 4.7.6 to 4.7.7. Changelog
Sourced from handlebars's changelog https://github.com/handlebars-lang/handlebars.js/blob/master/release-notes.md.
v4.7.7 - February 15th, 2021
- fix weird error in integration tests - eb860c0
- fix: check prototype property access in strict-mode (#1736 https://github-redirect.dependabot.com/wycats/handlebars.js/issues/1736)
- b6d3de7
- fix: escape property names in compat mode (#1736 https://github-redirect.dependabot.com/wycats/handlebars.js/issues/1736)
- f058970
- refactor: In spec tests, use expectTemplate over equals and shouldThrow (#1683 https://github-redirect.dependabot.com/wycats/handlebars.js/issues/1683)
- 77825f8
- chore: start testing on Node.js 12 and 13 - 3789a30
(POSSIBLY) BREAKING CHANGES:
- the changes from version 4.6.0 https://github.com/handlebars-lang/handlebars.js/blob/master/release-notes.md#v460---january-8th-2020 now also apply in when using the compile-option "strict: true". Access to prototype properties is forbidden completely by default, specific properties or methods can be allowed via runtime-options. See #1633 https://github-redirect.dependabot.com/wycats/handlebars.js/issues/1633 for details. If you are using Handlebars as documented, you should not be accessing prototype properties from your template anyway, so the changes should not be a problem for you. Only the use of undocumented features can break your build.
That is why we only bump the patch version despite mentioning breaking changes.
Commits https://github.com/wycats/handlebars.js/compare/v4.7.6...v4.7.7
Commits
- a9a8e40 https://github.com/handlebars-lang/handlebars.js/commit/a9a8e403213583ca90cb7c872d3a22796c37d961 v4.7.7
- e66aed5 https://github.com/handlebars-lang/handlebars.js/commit/e66aed5b99c1b6c93564f37d627e34e5d60eb76e Update release notes
- 7d4d170 https://github.com/handlebars-lang/handlebars.js/commit/7d4d170ce46a53084a41920c5c7387c131357989 disable IE in Saucelabs tests
- eb860c0 https://github.com/handlebars-lang/handlebars.js/commit/eb860c08998f8f506360d305d89e1f4b40f72a0a fix weird error in integration tests
- b6d3de7 https://github.com/handlebars-lang/handlebars.js/commit/b6d3de7123eebba603e321f04afdbae608e8fea8 fix: check prototype property access in strict-mode (#1736 https://github-redirect.dependabot.com/wycats/handlebars.js/issues/1736 )
- f058970 https://github.com/handlebars-lang/handlebars.js/commit/f0589701698268578199be25285b2ebea1c1e427 fix: escape property names in compat mode (#1736 https://github-redirect.dependabot.com/wycats/handlebars.js/issues/1736 )
- 77825f8 https://github.com/handlebars-lang/handlebars.js/commit/77825f8d3522356feb8e4160fac16344104d192b refator: In spec tests, use expectTemplate over equals and shouldThrow (
1683
https://github-redirect.dependabot.com/wycats/handlebars.js/issues/1683 )
- 3789a30 https://github.com/handlebars-lang/handlebars.js/commit/3789a309554fd600caeae442f40881cf93eb3b54 chore: start testing on Node.js 12 and 13
- See full diff in compare view https://github.com/wycats/handlebars.js/compare/v4.7.6...v4.7.7
[image: Dependabot compatibility score] https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- @dependabot rebase will rebase this PR
- @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
- @dependabot merge will merge this PR after your CI passes on it
- @dependabot squash and merge will squash and merge this PR after your CI passes on it
- @dependabot cancel merge will cancel a previously requested merge and block automerging
- @dependabot reopen will reopen this PR if it is closed
- @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
- @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
- @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
- @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the Security Alerts page https://github.com/JXA-userland/JXA/network/alerts.
You can view, comment on, or merge this pull request online at:
https://github.com/JXA-userland/JXA/pull/35 Commit Summary
- chore(deps): bump handlebars from 4.7.6 to 4.7.7
File Changes
- M yarn.lock https://github.com/JXA-userland/JXA/pull/35/files#diff-51e4f558fae534656963876761c95b83b6ef5da5103c4adef6768219ed76c2de (12)
Patch Links:
— You are receiving this because you are subscribed to this thread. Reply to this email directly, view it on GitHub https://github.com/JXA-userland/JXA/pull/35, or unsubscribe https://github.com/notifications/unsubscribe-auth/AAAE2AQMJYXPRRF6XLEP2YTTMO6S5ANCNFSM44JP4F7A .
Bumps handlebars from 4.7.6 to 4.7.7.
Changelog
Sourced from handlebars's changelog.
Commits
a9a8e40
v4.7.7e66aed5
Update release notes7d4d170
disable IE in Saucelabs testseb860c0
fix weird error in integration testsb6d3de7
fix: check prototype property access in strict-mode (#1736)f058970
fix: escape property names in compat mode (#1736)77825f8
refator: In spec tests, use expectTemplate over equals and shouldThrow (#1683)3789a30
chore: start testing on Node.js 12 and 13Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/JXA-userland/JXA/network/alerts).