Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security issues #89

Open
Poloten opened this issue Nov 25, 2019 · 1 comment
Open

Security issues #89

Poloten opened this issue Nov 25, 2019 · 1 comment

Comments

@Poloten
Copy link

Poloten commented Nov 25, 2019

 High            Prototype Pollution
 Package         handlebars
 Dependency of   webpack-spritesmith [dev]
 Path            webpack-spritesmith > spritesheet-templates > handlebars
 More info       https://npmjs.com/advisories/1164

  Moderate        Denial of Service
  Package         handlebars
  Dependency of   webpack-spritesmith [dev]
  Path            webpack-spritesmith > spritesheet-templates > handlebars
  More info       https://npmjs.com/advisories/1300

  High            Arbitrary Code Execution
  Package         handlebars
  Dependency of   webpack-spritesmith [dev]
  Path            webpack-spritesmith > spritesheet-templates > handlebars
  More info       https://npmjs.com/advisories/1316
                                                                                                                                                
  High            Arbitrary Code Execution
  Package         handlebars
  Dependency of   webpack-spritesmith [dev]
  Path            webpack-spritesmith > spritesheet-templates > handlebars
  More info       https://npmjs.com/advisories/1324
                                                                    
  High            Prototype Pollution
  Package         handlebars
  Dependency of   webpack-spritesmith [dev]
  Path            webpack-spritesmith > spritesheet-templates > handlebars
  More info       https://npmjs.com/advisories/1325

Hello it's possible to create new version with fix that securities issues ? #

@mixtur
Copy link
Owner

mixtur commented Nov 27, 2019

npm audit fix should help. I can raise minimum required version for spritesheet-templates but it won't help too much.
At least one of the security issues, is only fixed in [email protected], and current spritesheet-templates version (10.4.2) allows versions >= 4.4.5.

Though If you insist I will do it anyway)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants