Someguy123 / LiteVault

LiteVault - Secure Online Litecoin Wallet https://www.litevault.net
Other
23 stars 39 forks source link

[Snyk] Security upgrade express-handlebars from 1.1.0 to 3.0.0 #27

Open Someguy123 opened 3 years ago

Someguy123 commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 673/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.6
Remote Code Execution (RCE)
SNYK-JS-HANDLEBARS-1056767
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: express-handlebars The new version differs by 45 commits.
  • a707698 Bump package version to 3.0
  • 424e870 Version bump to object.assign and handlebars
  • 07f9bbd Revert "use sindresorhus's object-assign polyfill"
  • 5514a07 Fixed links
  • d005c83 v2.0.2
  • 14fa097 use handlebars 4.0.5 in shared template example
  • 41e99a1 updated glob and graceful-fs dependencies
  • 28335bc use sindresorhus's object-assign polyfill
  • 4c16ce4 Merge branch 'PaulBGD-patch-1'
  • c19c888 Update to the latest version of promise
  • 5769107 Merge branch 'blendlabs-master'
  • 71bac24 bump handlebars version to ^4.0.0
  • bdb5c32 2.0.1
  • 5407b37 Update HISTORY for 2.0.1
  • e3ba74c Address unexpected Handlebars API change
  • f6d9b58 2.0.0
  • 10c77ae Change HTML code blocks to Handlebars in README
  • d5e664b Update HISTORY for v2
  • 437b2cf Merge branch 'bug-113' of https://github.com/Tineler/express-handlebars into Tineler-bug-113
  • 0e3910c Update README docs for v2
  • f018a75 Move file system cache to instance state
  • 8e3c92a Merge pull request #105 from ericf/handlebars-3.0
  • 7adc509 Update package with license info
  • 5fc308e Merge branch 'license' of https://github.com/jconniff/express-handlebars into jconniff-license
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic