This repository was archived by the owner on Sep 21, 2022. It is now read-only.
Update dependency express-handlebars to v5 [SECURITY]#507
Open
renovate[bot] wants to merge 1 commit intomainfrom
Open
Update dependency express-handlebars to v5 [SECURITY]#507renovate[bot] wants to merge 1 commit intomainfrom
renovate[bot] wants to merge 1 commit intomainfrom
Conversation
6700671 to
e0ca83d
Compare
e0ca83d to
57a0644
Compare
57a0644 to
e09db59
Compare
e09db59 to
3de95ff
Compare
3de95ff to
4240e2f
Compare
4240e2f to
a5a8939
Compare
a5a8939 to
c57a4e6
Compare
c57a4e6 to
db1bd59
Compare
db1bd59 to
f588473
Compare
f588473 to
30ba040
Compare
19a4f9d to
697a4db
Compare
697a4db to
45d3505
Compare
6c7aa97 to
71f540b
Compare
71f540b to
ce42dbf
Compare
9fc90ca to
4ea3b9b
Compare
4ea3b9b to
70bbe6b
Compare
70bbe6b to
146026f
Compare
146026f to
3f3418c
Compare
3f3418c to
c5064ab
Compare
d253c1f to
358d7fd
Compare
358d7fd to
19931f6
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^4.0.4->^5.0.0GitHub Vulnerability Alerts
CVE-2021-32820
Express-handlebars is a Handlebars view engine for Express. Express-handlebars mixes pure template data with engine configuration options through the Express render API. More specifically, the layout parameter may trigger file disclosure vulnerabilities in downstream applications. This potential vulnerability is somewhat restricted in that only files with existing extentions (i.e. file.extension) can be included, files that lack an extension will have .handlebars appended to them. For complete details refer to the referenced GHSL-2021-018 report. Notes in documentation have been added to help users avoid this potential information exposure vulnerability.
A fix is discussed in https://github.com/express-handlebars/express-handlebars/pull/163
Release Notes
express-handlebars/express-handlebars
v5.3.1Compare Source
Bug Fixes
v5.3.0Compare Source
Features
5.2.1 (2021-02-16)
Bug Fixes
v5.2.1Compare Source
Bug Fixes
v5.2.0Compare Source
Features
v5.1.0Compare Source
Features
v5.0.0Compare Source
Bug Fixes
BREAKING CHANGES
4.0.6 (2020-07-06)
Bug Fixes
4.0.5 (2020-07-03)
Bug Fixes
4.0.4 (2020-04-29)
Bug Fixes
4.0.3 (2020-04-05)
Bug Fixes
4.0.2 (2020-04-03)
Bug Fixes
Configuration
📅 Schedule: "" (UTC).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by WhiteSource Renovate. View repository job log here.