From 8bc8bad7993bcb77b81b1643ed88e1a231249273 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Tue, 4 May 2021 23:28:23 +0000 Subject: [PATCH] fix: package.json & package-lock.json to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-HANDLEBARS-1279029 --- package-lock.json | 32 ++++++++++++++++++++++++++++---- package.json | 2 +- 2 files changed, 29 insertions(+), 5 deletions(-) mode change 100755 => 100644 package.json diff --git a/package-lock.json b/package-lock.json index b0a9086..5b94c0c 100644 --- a/package-lock.json +++ b/package-lock.json @@ -2971,12 +2971,36 @@ } }, "hbs": { - "version": "4.1.0", - "resolved": "https://registry.npmjs.org/hbs/-/hbs-4.1.0.tgz", - "integrity": "sha512-YDrUBtLpwRl0H5uyCGLE2LGtGJl51VvJFBj/D+Cqyr6XMopCvwXA0ynRpd87u6aVIYCeGYZHESfZzPHbNMkOPA==", + "version": "4.1.2", + "resolved": "https://registry.npmjs.org/hbs/-/hbs-4.1.2.tgz", + "integrity": "sha512-WfBnQbozbdiTLjJu6P6Wturgvy0FN8xtRmIjmP0ebX9OGQrt+2S6UC7xX0IebHTCS1sXe20zfTzQ7yhjrEvrfQ==", "requires": { - "handlebars": "4.5.3", + "handlebars": "4.7.7", "walk": "2.3.14" + }, + "dependencies": { + "handlebars": { + "version": "4.7.7", + "resolved": "https://registry.npmjs.org/handlebars/-/handlebars-4.7.7.tgz", + "integrity": "sha512-aAcXm5OAfE/8IXkcZvCepKU3VzW1/39Fb5ZuqMtgI/hT8X2YgoMvBY5dLhq/cpOvw7Lk1nK/UF71aLG/ZnVYRA==", + "requires": { + "minimist": "^1.2.5", + "neo-async": "^2.6.0", + "source-map": "^0.6.1", + "uglify-js": "^3.1.4", + "wordwrap": "^1.0.0" + } + }, + "minimist": { + "version": "1.2.5", + "resolved": "https://registry.npmjs.org/minimist/-/minimist-1.2.5.tgz", + "integrity": "sha512-FM9nNUYrRBAELZQT3xeZQ7fmMOBg6nWNmJKTcgsJeaLstP/UODVpGsr5OhXhhXg6f+qtJ8uiZ+PUxkDWcgIXLw==" + }, + "wordwrap": { + "version": "1.0.0", + "resolved": "https://registry.npmjs.org/wordwrap/-/wordwrap-1.0.0.tgz", + "integrity": "sha1-J1hIEIkUVqQXHI0CJkQa3pDLyus=" + } } }, "he": { diff --git a/package.json b/package.json old mode 100755 new mode 100644 index 1a0be2d..2193c8d --- a/package.json +++ b/package.json @@ -37,7 +37,7 @@ "express-handlebars": "^3.1.0", "fs": "0.0.1-security", "gm": "^1.23.1", - "hbs": "^4.1.0", + "hbs": "^4.1.2", "helmet": "^3.21.2", "is-uuid": "^1.0.2", "md5": "^2.2.1",