-
Notifications
You must be signed in to change notification settings - Fork 0
build(deps): [security] bump handlebars from 4.0.12 to 4.1.0 #6
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
build(deps): [security] bump handlebars from 4.0.12 to 4.1.0 #6
Conversation
|
Code Climate has analyzed commit 313cb4f and detected 0 issues on this pull request. The test coverage on the diff in this pull request is 100.0% (50% is the threshold). This pull request will bring the total coverage in the repository to 100.0% (0.0% change). View more on Code Climate. |
|
Dependabot tried to automerge this PR, but received the following error from GitHub: As a result, we've disabled automerging on this repo (you can re-enable it in your Dependabot settings). |
d90b79f to
d52fef5
Compare
gregswindle
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
If the status checks all pass, this LGTM! 👍
- @dependabot squash and merge
|
Annoyingly, that came through to me on Dependabot support, so it hasn't picked it up. I'll fix it so it does next time you comment like that, though! |
d52fef5 to
c244f88
Compare
gregswindle
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
As long as the rebase has no issues and all qa-gates pass, this LGTM 👍
@dependabot squash and merge
Bumps [handlebars](https://github.com/wycats/handlebars.js) from 4.0.12 to 4.1.0. **This update includes security fixes.** - [Release notes](https://github.com/wycats/handlebars.js/releases) - [Changelog](https://github.com/wycats/handlebars.js/blob/v4.1.0/release-notes.md) - [Commits](handlebars-lang/handlebars.js@v4.0.12...v4.1.0) Signed-off-by: dependabot[bot] <support@dependabot.com>
c244f88 to
313cb4f
Compare
gregswindle
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Bumps handlebars from 4.0.12 to 4.1.0. This update includes security fixes.
Vulnerabilities fixed
Sourced from The npm Advisory Database.
Changelog
Sourced from handlebars's changelog.
Commits
7caca94v4.1.07bd34fbUpdate release notes56fc676test: run appveyor tests in Node 10ee30222chore: disable sauce-labs05e6293chore: bump version of grunt-saucelabs2db0d12chore: add .idea and yarn-error.log to .gitignoreedc6220fix: disallow access to the constructor in templates to prevent RCEbacd473chore: fix components/handlebars package.json and auto-update on release27ac1eeFeat: Import TypeScript typings78dd89cchore: Use node 10 to build handlebarsDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot will merge this PR once CI passes on it, as requested by @gregswindle.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge@dependabot reopenwill reopen this PR if it is closed@dependabot ignore this [patch|minor|major] versionwill close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)@dependabot use these labelswill set the current labels as the default for future PRs for this repo and language@dependabot use these reviewerswill set the current reviewers as the default for future PRs for this repo and language@dependabot use these assigneeswill set the current assignees as the default for future PRs for this repo and language@dependabot use this milestonewill set the current milestone as the default for future PRs for this repo and language@dependabot badge mewill comment on this PR with code to add a "Dependabot enabled" badge to your readmeAdditionally, you can set the following in your Dependabot dashboard:
Finally, you can contact us by mentioning @dependabot.