Skip to content
This repository has been archived by the owner on Dec 8, 2024. It is now read-only.

Depends on handlebars v4.0.1 which has a severe security vulnerability #920

Open
IanKemp opened this issue Sep 26, 2019 · 3 comments
Open

Comments

@IanKemp
Copy link

IanKemp commented Sep 26, 2019

Please see https://www.npmjs.com/advisories/1164

@Cazaimi
Copy link

Cazaimi commented Oct 10, 2019

Also see: https://app.snyk.io/vuln/npm:istanbul

@gotwarlost , any ETA on this?

@IanKemp
Copy link
Author

IanKemp commented Oct 10, 2019

BTW, I'm fully aware that this package is deprecated, but a lot of projects still depend on it, hence why I think a release just to update the dependencies would be justified.

@mailmrmanoj
Copy link

+1

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants