Replies: 2 comments 3 replies
-
See #1841 (comment). Thanks for the suggestion on dependabot, but we already get notified about security issues by GitHub. |
Beta Was this translation helpful? Give feedback.
1 reply
-
if there is a security issue with handlebars or its dependencies, we update our code as soon as possible. |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
hello,
i've just opened a PR for updating a lot of dependencies that are outdated: #1841
please merge it and release a new version, as currently handlebars suffers from a critical CVE originating from minimist, see here: GHSA-xvch-5gv4-984h
on the same subject, i think degradation of the package-lock file can be avoided or at least be minimal by applying dependabot to this repo, to help keep dependencies in sync.
Beta Was this translation helpful? Give feedback.
All reactions