frappe / datatable

The Missing Javascript Datatable for the Web
https://frappe.io/datatable
MIT License
1.02k stars 164 forks source link

Vulnerability due to handlebars : upgrade doesn't cause any dependency clashes #79

Closed coderkoala closed 5 years ago

coderkoala commented 5 years ago

The dependency handlebar currently has an issue, of moderate severity. I tried updating and unit testing a few cases, and so far it's good. Is it possible for frappe to update the security vulnerability?

For clarity, any version of handlebar >=4.1.0 should warrant for it.

Best, Nobel