Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[Snyk] Upgrade handlebars from 4.0.11 to 4.7.8 #2

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

danielsb74
Copy link
Owner

snyk-top-banner

Snyk has created this PR to upgrade handlebars from 4.0.11 to 4.7.8.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 36 versions ahead of your current version.

  • The recommended version was released on a year ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Prototype Pollution
SNYK-JS-HANDLEBARS-173692
601 No Known Exploit
high severity Prototype Pollution
SNYK-JS-HANDLEBARS-174183
601 No Known Exploit
high severity Prototype Pollution
SNYK-JS-HANDLEBARS-469063
601 No Known Exploit
high severity Denial of Service (DoS)
SNYK-JS-HANDLEBARS-480388
601 No Known Exploit
high severity Arbitrary Code Execution
SNYK-JS-HANDLEBARS-534478
601 Proof of Concept
medium severity Prototype Pollution
SNYK-JS-HANDLEBARS-1279029
601 Proof of Concept
critical severity Prototype Pollution
SNYK-JS-HANDLEBARS-534988
601 No Known Exploit
high severity Remote Code Execution (RCE)
SNYK-JS-HANDLEBARS-1056767
601 Proof of Concept
medium severity Prototype Pollution
SNYK-JS-HANDLEBARS-567742
601 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-UGLIFYJS-1727251
601 No Known Exploit
Release notes
Package name: handlebars
  • 4.7.8 - 2023-08-01
    • Make library compatible with workers (#1894) - 3d3796c
    • Don't rely on Node.js global object (#1776) - 2954e7e
    • Fix compiling of each block params in strict mode (#1855) - 30dbf04
    • Fix rollup warning when importing Handlebars as ESM - 03d387b
    • Fix bundler issue with webpack 5 (#1862) - c6c6bbb
    • Use https instead of git for mustache submodule - 88ac068

    Commits

  • 4.7.7 - 2021-02-15

    v4.7.7

  • 4.7.6 - 2020-04-03

    v4.7.6

  • 4.7.5 - 2020-04-02

    v4.7.5

  • 4.7.4 - 2020-04-01

    v4.7.4

  • 4.7.3 - 2020-02-05

    v4.7.3

  • 4.7.2 - 2020-01-13

    v4.7.2

  • 4.7.1 - 2020-01-12

    v4.7.1

  • 4.7.0 - 2020-01-10

    v4.7.0

  • 4.6.0 - 2020-01-08
  • 4.5.3 - 2019-11-18
  • 4.5.2 - 2019-11-13
  • 4.5.1 - 2019-10-29
  • 4.5.0 - 2019-10-28
  • 4.4.5 - 2019-10-20
  • 4.4.4 - 2019-10-20
  • 4.4.3 - 2019-10-08
  • 4.4.2 - 2019-10-02
  • 4.4.1 - 2019-10-02
  • 4.4.0 - 2019-09-29
  • 4.3.5 - 2019-10-02
  • 4.3.4 - 2019-09-28
  • 4.3.3 - 2019-09-27
  • 4.3.2 - 2019-09-26
  • 4.3.1 - 2019-09-24
  • 4.3.0 - 2019-09-24
  • 4.2.2 - 2019-10-02
  • 4.2.1 - 2019-09-20
  • 4.2.0 - 2019-09-03
  • 4.1.2 - 2019-04-13
  • 4.1.2-0 - 2019-08-25
  • 4.1.1 - 2019-03-16
  • 4.1.0 - 2019-02-07
  • 4.0.14 - 2019-04-13
  • 4.0.13 - 2019-02-07
  • 4.0.12 - 2018-09-04
  • 4.0.11 - 2017-10-17
from handlebars GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade handlebars from 4.0.11 to 4.7.8.

See this package in npm:
handlebars

See this project in Snyk:
https://app.snyk.io/org/danielsb74/project/d4de5ecd-fb06-4c70-94e6-f0fed583c188?utm_source=github&utm_medium=referral&page=upgrade-pr
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants