Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

@glimmer/syntax: Bump minimum handlebars.js version #1071

Merged
merged 1 commit into from
Apr 15, 2020
Merged

@glimmer/syntax: Bump minimum handlebars.js version #1071

merged 1 commit into from
Apr 15, 2020

Conversation

dcyriller
Copy link
Contributor

..from 4.5.1 to 4.7.4

In v4.7.4, handlebars.js dropped optimist dependency. This optimist
dep had a dependency on an outdated version of minimist affected by
CVE-2020-7598.

This will remove a Github security alert in packages depending on
@glimmer/syntax.

For the sake of consistency, I bumped the main the version in the main
package.json as well. Not sure if it is legit though.

..version from 4.5.1 to 4.7.4

In v4.7.4, handlebars.js dropped `optimist` dependency. This `optimist`
dep had a dependency on an outdated version of `minimist` affected by
CVE-2020-7598. Here the Github warning:
GHSA-vh95-rmgr-6w4m

This will remove a Github security alert in packages depending on
@glimmer/syntax.

For the sake of consistency, I bumped the main the version in the main
package.json as well.
@rwjblue
Copy link
Member

rwjblue commented Apr 15, 2020

Thank you @dcyriller!

@rwjblue rwjblue added the bug label Apr 15, 2020
@rwjblue rwjblue merged commit 80b2a35 into glimmerjs:master Apr 15, 2020
@rwjblue
Copy link
Member

rwjblue commented Apr 15, 2020

Published as v0.50.3.

@dcyriller dcyriller deleted the bump-handlebars branch April 15, 2020 16:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants