cblanc / sws_gathers

NSL Gathers App
http://gathers.ensl.org
8 stars 9 forks source link

[Snyk] Security upgrade express-handlebars from 2.0.1 to 3.0.0 #161

Closed snyk-bot closed 4 years ago

snyk-bot commented 4 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
medium severity Prototype Pollution
SNYK-JS-HANDLEBARS-567742
Yes Proof of Concept
Commit messages
Package name: express-handlebars The new version differs by 12 commits.
  • a707698 Bump package version to 3.0
  • 424e870 Version bump to object.assign and handlebars
  • 07f9bbd Revert "use sindresorhus's object-assign polyfill"
  • 5514a07 Fixed links
  • d005c83 v2.0.2
  • 14fa097 use handlebars 4.0.5 in shared template example
  • 41e99a1 updated glob and graceful-fs dependencies
  • 28335bc use sindresorhus's object-assign polyfill
  • 4c16ce4 Merge branch 'PaulBGD-patch-1'
  • c19c888 Update to the latest version of promise
  • 5769107 Merge branch 'blendlabs-master'
  • 71bac24 bump handlebars version to ^4.0.0
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:

🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic