wix-incubator / lerna-script

Lerna addon for adding custom tasks
MIT License
164 stars 13 forks source link

fix(deps): update dependency handlebars to v4.7.7 [security] #442

Open renovate[bot] opened 3 years ago

renovate[bot] commented 3 years ago

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
handlebars (source) 4.7.6 -> 4.7.7 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2021-23369

The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.

CVE-2021-23383

The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.


Release Notes

wycats/handlebars.js ### [`v4.7.7`](https://togithub.com/wycats/handlebars.js/blob/HEAD/release-notes.md#v477---February-15th-2021) [Compare Source](https://togithub.com/wycats/handlebars.js/compare/v4.7.6...v4.7.7) - fix weird error in integration tests - [`eb860c0`](https://togithub.com/wycats/handlebars.js/commit/eb860c0) - fix: check prototype property access in strict-mode ([#​1736](https://togithub.com/wycats/handlebars.js/issues/1736)) - [`b6d3de7`](https://togithub.com/wycats/handlebars.js/commit/b6d3de7) - fix: escape property names in compat mode ([#​1736](https://togithub.com/wycats/handlebars.js/issues/1736)) - [`f058970`](https://togithub.com/wycats/handlebars.js/commit/f058970) - refactor: In spec tests, use expectTemplate over equals and shouldThrow ([#​1683](https://togithub.com/wycats/handlebars.js/issues/1683)) - [`77825f8`](https://togithub.com/wycats/handlebars.js/commit/77825f8) - chore: start testing on Node.js 12 and 13 - [`3789a30`](https://togithub.com/wycats/handlebars.js/commit/3789a30) (POSSIBLY) BREAKING CHANGES: - the changes from version [4.6.0](https://togithub.com/handlebars-lang/handlebars.js/blob/master/release-notes.md#v460---january-8th-2020) now also apply in when using the compile-option "strict: true". Access to prototype properties is forbidden completely by default, specific properties or methods can be allowed via runtime-options. See [#​1633](https://togithub.com/wycats/handlebars.js/issues/1633) for details. If you are using Handlebars as documented, you should not be accessing prototype properties from your template anyway, so the changes should not be a problem for you. Only the use of undocumented features can break your build. That is why we only bump the patch version despite mentioning breaking changes. [Commits](https://togithub.com/handlebars-lang/handlebars.js/compare/v4.7.6...v4.7.7)

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.



This PR has been generated by Mend Renovate. View repository job log here.