ericf / express-handlebars

A Handlebars view engine for Express which doesn't suck.
BSD 3-Clause "New" or "Revised" License
2.31k stars 384 forks source link

🚨 Security Update: handlebars dependency 🚨 #243

Closed asos-albinotonnina closed 5 years ago

asos-albinotonnina commented 5 years ago

A vulnerability has been found in handlebars@4.0.12

This PR updated to @4.0.13

vulnerability report: https://snyk.io/vuln/SNYK-JS-HANDLEBARS-173692

commit: https://github.com/wycats/handlebars.js/commit/7372d4e9dffc9d70c09671aa28b9392a1577fd86

asos-albinotonnina commented 5 years ago

Thank you so much for the approval @benjipott Do you think you're going to publish on npm? Last version, 3.0.0, is 3 years old..

benjipott commented 5 years ago

I don't have any access to merge or publish, sorry

sahat commented 5 years ago

I have published a new version 3.0.1 to NPM with the updated dependencies.

asos-albinotonnina commented 5 years ago

Great news! Thank you very much @sahat, much appreciated!