This repository was archived by the owner on Sep 21, 2022. It is now read-only.
Update dependency express-handlebars to v5 [SECURITY]#507
Open
renovate[bot] wants to merge 1 commit intomainfrom
Open
Update dependency express-handlebars to v5 [SECURITY]#507renovate[bot] wants to merge 1 commit intomainfrom
renovate[bot] wants to merge 1 commit intomainfrom
Conversation
6700671 to
e0ca83d
Compare
e0ca83d to
57a0644
Compare
57a0644 to
e09db59
Compare
e09db59 to
3de95ff
Compare
3de95ff to
4240e2f
Compare
4240e2f to
a5a8939
Compare
a5a8939 to
c57a4e6
Compare
c57a4e6 to
db1bd59
Compare
db1bd59 to
f588473
Compare
f588473 to
30ba040
Compare
3a24feb to
791930f
Compare
791930f to
f7fe660
Compare
f7fe660 to
8bb6358
Compare
8bb6358 to
125a785
Compare
125a785 to
83b4a5a
Compare
83b4a5a to
0420d39
Compare
0420d39 to
7d4178e
Compare
7d4178e to
cf12de3
Compare
cf12de3 to
747e6a8
Compare
747e6a8 to
ef7a013
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^4.0.4->^5.0.0GitHub Vulnerability Alerts
CVE-2021-32820
Express-handlebars is a Handlebars view engine for Express. Express-handlebars mixes pure template data with engine configuration options through the Express render API. More specifically, the layout parameter may trigger file disclosure vulnerabilities in downstream applications. This potential vulnerability is somewhat restricted in that only files with existing extentions (i.e. file.extension) can be included, files that lack an extension will have .handlebars appended to them. For complete details refer to the referenced GHSL-2021-018 report. Notes in documentation have been added to help users avoid this potential information exposure vulnerability.
A fix is discussed in https://github.com/express-handlebars/express-handlebars/pull/163
Release Notes
express-handlebars/express-handlebars
v5.3.1Compare Source
Bug Fixes
v5.3.0Compare Source
Features
5.2.1 (2021-02-16)
Bug Fixes
v5.2.1Compare Source
Bug Fixes
v5.2.0Compare Source
Features
v5.1.0Compare Source
Features
v5.0.0Compare Source
Bug Fixes
BREAKING CHANGES
4.0.6 (2020-07-06)
Bug Fixes
4.0.5 (2020-07-03)
Bug Fixes
4.0.4 (2020-04-29)
Bug Fixes
4.0.3 (2020-04-05)
Bug Fixes
4.0.2 (2020-04-03)
Bug Fixes
Configuration
📅 Schedule: "" (UTC).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by WhiteSource Renovate. View repository job log here.