Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Release for handlebars dependency #70

Open
kevindb opened this issue Dec 5, 2017 · 6 comments
Open

Release for handlebars dependency #70

kevindb opened this issue Dec 5, 2017 · 6 comments
Assignees
Milestone

Comments

@kevindb
Copy link

kevindb commented Dec 5, 2017

I use grunt-githooks as a dev-dependency in jquery-form. Github is now alerting me to a moderate severity security vulnerability in handlebars < 4.0.0. I see that PR #65 updated handlebars in dev, and it tagged for release 0.7.0. Would it be possible to release 0.7.0, even if it's just for updating handlebars?
Thank you

@franz-josef-kaiser franz-josef-kaiser self-assigned this Dec 7, 2017
@franz-josef-kaiser franz-josef-kaiser added this to the 0.7.0 milestone Dec 7, 2017
@franz-josef-kaiser
Copy link
Member

@kevindb Have you tested it? (It's the dev-Branch).

@kevindb
Copy link
Author

kevindb commented Dec 7, 2017

I see on the PR that the TravisCI build passed. But no, I have not tested it in jquery-form. I'm not aware of a way I can use grunt-githooks's dev branch via npm.

@franz-josef-kaiser
Copy link
Member

@kevindb Thats easy: https://stackoverflow.com/a/39732501

Please give it a try!

@Rudloff
Copy link

Rudloff commented Sep 28, 2019

Any news on this?
Handlebars 1 has several vulnerabilities:

@franz-josef-kaiser
Copy link
Member

@Rudloff this repo is not under active development, but I am happy to merge any PR to fix vulnerabilities. In case you can at least provide a fix, code samples or would be willing to test an update, I am happy to update and release a new version including the fix. Works for you?

Rudloff added a commit to Rudloff/openvegemap that referenced this issue Oct 13, 2019
@Rudloff
Copy link

Rudloff commented Oct 13, 2019

I force-upgraded handlebars in one of my projects and it seems to work correctly.
However, I am not using a custom template so I might not be the best person to test this.

georgettodd added a commit to georgettodd/openvegemap that referenced this issue Apr 13, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants