Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade dependencies #45

Merged
merged 1 commit into from Mar 12, 2018
Merged

Upgrade dependencies #45

merged 1 commit into from Mar 12, 2018

Conversation

zachelrath
Copy link
Contributor

@zachelrath zachelrath commented Mar 7, 2018

Summary of Changes

  • Addresses Package dependencies security: upgrade Handlebars to 4.0.0 #44
  • Upgrades async dependency, which has known CVE's.
  • Upgrades handlebars dependency, which has known CVE's.
  • Upgrades mocha to fix travis CI build issues
  • Upgrades should
  • Adjusts Travis build to run against active LTS (8.10.x) and current (9.7.x).
  • Commit the package-lock.json so that (a) NPM installs are faster (b) Github's dependency graph scanning can pick up on dependency vulnerabilities and report them automatically.

@zachelrath zachelrath changed the title Upgrade handlebars and async, and add package-lock Upgrade dependencies Mar 7, 2018
@zachelrath
Copy link
Contributor Author

@kevinohara80 Any thoughts on this?

@kevinohara80
Copy link
Owner

Looks good from my phone ;)

I’ll get this merged tomorrow!

@zachelrath
Copy link
Contributor Author

Thanks Kevin, appreciate it!

@zachelrath
Copy link
Contributor Author

@kevinohara80 Any update on this?

@kevinohara80 kevinohara80 merged commit 88ded41 into kevinohara80:master Mar 12, 2018
@kevinohara80
Copy link
Owner

Sorry for the delay. Published in 1.5.2

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants