trilbymedia / grav-plugin-git-sync

Collaboratively Synchronize your Grav `user` folder hosted on GitHub, BitBucket or GitLab
Apache License 2.0
240 stars 58 forks source link

Multiple security reports #158

Closed RCheesley closed 4 years ago

RCheesley commented 4 years ago

Hi there,

Dependabot just went a little crazy on my Grav repo, pointing at multiple dependency issues with this plugin. As far as I'm aware, I'm up to date with the latest version of the plugin, so not sure if there are going to be updates in the future to address these?

The main critical alerts seem to be lodash, mixin-deep, js-yaml and eslint-utils.

w00fz commented 4 years ago

I fixed them, thanks

RCheesley commented 4 years ago

Perfect thank you! Presume that a release will come out in due course? Much appreciated!

w00fz commented 4 years ago

Hope this week, there's some other changes in the pipe that will make GitSync depending on minimum Grav 1.6 and I'm trying to make sure there's no bad implications with that.

You could download the zip from develop if you have urgency of using the latest and greatest.

RCheesley commented 4 years ago

OK that's perfect, thank you for the info!

RCheesley commented 4 years ago

Any ideas when the next release might be coming? Will grab the develop zip if it's not going to be imminent as we're about to launch our platform and would rather do that without known vulnerabilities :)

w00fz commented 4 years ago

Sorry I’ve been focused on other projects and I forgot about the release of gitsync. I’ll try to get it out today.

RCheesley commented 4 years ago

Wonderful, thank you very much! :)

w00fz commented 4 years ago

Released now! Should be appearing on GPM soon.

Thanks