sintaxi / harp

Static Web Server/Generator/Bundler
http://harpjs.com
4.99k stars 346 forks source link

fix all known major and critical security issues #647

Closed marcoemrich closed 5 years ago

marcoemrich commented 5 years ago

mostly an upgrade to connect 3.4.1 was necessary.

This required using the new external basic-auth package since connect.basicAuth is no longer available, see http://www.senchalabs.org/connect/basicAuth.html

also did several (conservative npm audit fixes) and upgraded mocha to 6.x

marcoemrich commented 5 years ago

this is an update of PR #645 with the broken test fixed (i.e. downgrade of send to 0.15.6)