node-gh / gh

(DEPRECATED) GitHub CLI made with NodeJS. Use the official https://cli.github.com/ instead.
http://nodegh.io
Other
1.71k stars 217 forks source link

[Snyk] Fix for 2 vulnerabilities #744

Closed snyk-bot closed 4 years ago

snyk-bot commented 4 years ago

Snyk has created this PR to fix one or more vulnerable packages in the npm dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Title Issue ID Breaking Change
high severity Arbitrary Code Execution SNYK-JS-HANDLEBARS-534478
high severity Prototype Pollution SNYK-JS-HANDLEBARS-534988

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:

🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

protoEvangelion commented 4 years ago

:tada: This PR is included in version 2.8.2 :tada:

The release is available on:

Your semantic-release bot :package::rocket: