-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update dependency handlebars to v4.7.4 (main) #53
Open
mend-for-github-com
wants to merge
1
commit into
main
Choose a base branch
from
whitesource-remediate/main-handlebars-4.x
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Update dependency handlebars to v4.7.4 (main) #53
mend-for-github-com
wants to merge
1
commit into
main
from
whitesource-remediate/main-handlebars-4.x
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
mend-for-github-com
bot
changed the title
Update dependency handlebars to v4.5.3 (main)
Update dependency handlebars to v4.7.4 (main)
Aug 18, 2022
mend-for-github-com
bot
force-pushed
the
whitesource-remediate/main-handlebars-4.x
branch
from
August 18, 2022 07:22
ce20b97
to
208b6a4
Compare
mend-for-github-com
bot
changed the title
Update dependency handlebars to v4.7.4 (main)
Update dependency handlebars to v4.5.3 (main)
Aug 23, 2022
mend-for-github-com
bot
force-pushed
the
whitesource-remediate/main-handlebars-4.x
branch
from
August 23, 2022 07:39
208b6a4
to
3c41241
Compare
mend-for-github-com
bot
changed the title
Update dependency handlebars to v4.5.3 (main)
Update dependency handlebars to v4.7.4 (main)
Aug 25, 2022
mend-for-github-com
bot
force-pushed
the
whitesource-remediate/main-handlebars-4.x
branch
from
August 25, 2022 18:36
3c41241
to
d8ec083
Compare
mend-for-github-com
bot
changed the title
Update dependency handlebars to v4.7.4 (main)
Update dependency handlebars to v4.5.3 (main)
Sep 5, 2022
mend-for-github-com
bot
force-pushed
the
whitesource-remediate/main-handlebars-4.x
branch
from
September 5, 2022 13:50
d8ec083
to
e5a58c0
Compare
mend-for-github-com
bot
changed the title
Update dependency handlebars to v4.5.3 (main)
Update dependency handlebars to v4.7.4 (main)
Sep 9, 2022
mend-for-github-com
bot
force-pushed
the
whitesource-remediate/main-handlebars-4.x
branch
from
September 9, 2022 15:29
e5a58c0
to
3de3190
Compare
mend-for-github-com
bot
changed the title
Update dependency handlebars to v4.7.4 (main)
Update dependency handlebars to v4.5.3 (main)
Sep 14, 2022
mend-for-github-com
bot
force-pushed
the
whitesource-remediate/main-handlebars-4.x
branch
from
September 14, 2022 12:33
3de3190
to
855fc35
Compare
mend-for-github-com
bot
changed the title
Update dependency handlebars to v4.5.3 (main)
Update dependency handlebars to v4.7.4 (main)
Sep 17, 2022
mend-for-github-com
bot
force-pushed
the
whitesource-remediate/main-handlebars-4.x
branch
from
September 17, 2022 12:17
855fc35
to
1758cc0
Compare
mend-for-github-com
bot
changed the title
Update dependency handlebars to v4.7.4 (main)
Update dependency handlebars to v4.5.3 (main)
Oct 18, 2022
mend-for-github-com
bot
force-pushed
the
whitesource-remediate/main-handlebars-4.x
branch
from
October 18, 2022 18:23
1758cc0
to
2b916a0
Compare
mend-for-github-com
bot
changed the title
Update dependency handlebars to v4.5.3 (main)
Update dependency handlebars to v4.7.4 (main)
Oct 22, 2022
mend-for-github-com
bot
force-pushed
the
whitesource-remediate/main-handlebars-4.x
branch
from
October 22, 2022 12:25
2b916a0
to
94f15b2
Compare
mend-for-github-com
bot
force-pushed
the
whitesource-remediate/main-handlebars-4.x
branch
from
November 20, 2022 20:52
94f15b2
to
3676f7d
Compare
mend-for-github-com
bot
changed the title
Update dependency handlebars to v4.7.4 (main)
Update dependency handlebars to v4.0.13 (main)
Nov 20, 2022
mend-for-github-com
bot
force-pushed
the
whitesource-remediate/main-handlebars-4.x
branch
from
March 26, 2023 18:14
3676f7d
to
c1aa270
Compare
mend-for-github-com
bot
changed the title
Update dependency handlebars to v4.0.13 (main)
Update dependency handlebars to v4.7.4 (main)
Mar 26, 2023
mend-for-github-com
bot
force-pushed
the
whitesource-remediate/main-handlebars-4.x
branch
from
March 27, 2023 10:17
c1aa270
to
ac61431
Compare
mend-for-github-com
bot
changed the title
Update dependency handlebars to v4.7.4 (main)
Update dependency handlebars to v4.5.3 (main)
Mar 27, 2023
mend-for-github-com
bot
force-pushed
the
whitesource-remediate/main-handlebars-4.x
branch
from
March 31, 2023 05:58
ac61431
to
4df4dea
Compare
mend-for-github-com
bot
changed the title
Update dependency handlebars to v4.5.3 (main)
Update dependency handlebars to v4.7.4 (main)
Mar 31, 2023
mend-for-github-com
bot
force-pushed
the
whitesource-remediate/main-handlebars-4.x
branch
from
April 23, 2023 11:36
4df4dea
to
8c00d8f
Compare
mend-for-github-com
bot
changed the title
Update dependency handlebars to v4.7.4 (main)
Update dependency handlebars to v4.5.3 (main)
Apr 23, 2023
mend-for-github-com
bot
force-pushed
the
whitesource-remediate/main-handlebars-4.x
branch
from
April 24, 2023 11:26
8c00d8f
to
4ac3e4d
Compare
mend-for-github-com
bot
changed the title
Update dependency handlebars to v4.5.3 (main)
Update dependency handlebars to v4.7.4 (main)
Apr 24, 2023
mend-for-github-com
bot
force-pushed
the
whitesource-remediate/main-handlebars-4.x
branch
from
June 14, 2023 21:33
4ac3e4d
to
07e8205
Compare
mend-for-github-com
bot
changed the title
Update dependency handlebars to v4.7.4 (main)
Update dependency handlebars to v4.5.3 (main)
Jun 14, 2023
mend-for-github-com
bot
force-pushed
the
whitesource-remediate/main-handlebars-4.x
branch
from
June 18, 2023 12:08
07e8205
to
d900663
Compare
mend-for-github-com
bot
changed the title
Update dependency handlebars to v4.5.3 (main)
Update dependency handlebars to v4.7.4 (main)
Jun 18, 2023
mend-for-github-com
bot
force-pushed
the
whitesource-remediate/main-handlebars-4.x
branch
from
April 2, 2024 18:05
d900663
to
d5e6ddc
Compare
mend-for-github-com
bot
changed the title
Update dependency handlebars to v4.7.4 (main)
Update dependency handlebars to v4.5.3 (main)
Apr 2, 2024
mend-for-github-com
bot
force-pushed
the
whitesource-remediate/main-handlebars-4.x
branch
from
April 4, 2024 12:08
d5e6ddc
to
05f4878
Compare
mend-for-github-com
bot
changed the title
Update dependency handlebars to v4.5.3 (main)
Update dependency handlebars to v4.7.4 (main)
Apr 4, 2024
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.0.10
->4.7.4
By merging this PR, the issue #4 will be automatically resolved and closed:
Release Notes
handlebars-lang/handlebars.js (handlebars)
v4.7.4
Compare Source
Chore/Housekeeping:
Compatibility notes:
Commits
v4.7.3
Compare Source
Chore/Housekeeping:
d78cc73
Bugfixes:
4de51fe
a32d05f
Compatibility notes:
Commits
v4.7.2
Compare Source
Bugfixes:
9d5aa36
, #1639Chore/Build:
a4fd391
Compatibility notes:
Commits
v4.7.1
Compare Source
Bugfixes:
f152dfc
3c1e252
Compatibility notes:
Commits
v4.7.0
Compare Source
Features:
7af1c12
, #1635and no explicit configuration has taken place.
Compatibility notes:
Commits
v4.6.0
Compare Source
Features:
d03b6ec
Bugfixes:
23d58e7
Chores, docs:
d7f0dcf
,187d611
,d337f40
c40d9f3
,8901c28
,e97685e
,1f61f21
164b7ff
,1ebce2b
14b621c
,1ec1737
,3a5b65e
,dde108e
,04b1984
,587e7a3
e913dc5
,ac4655e
,dc54952
d1fb07b
edcc84f
BREAKING CHANGES:
access to prototype properties is forbidden completely by default,
specific properties or methods can be allowed via runtime-options.
See #1633 for details.
If you are using Handlebars as documented, you should not be accessing prototype
properties from your template anyway, so the changes should not be a problem
for you. Only the use of undocumented features can break your build.
That is why we only bump the minor version despite mentioning breaking changes.
Commits
v4.5.3
Compare Source
Bugfixes:
f7f05d7
1988878
Chores / Build:
c02b05f
deprecate old assertion-methods -
93e284e
,886ba86
,0817dad
,93516a0
Security:
__proto__
,__defineGetter__
,__defineSetter__
and__lookupGetter__
have been added to the list of "properties that must be enumerable".
If a property by that name is found and not enumerable on its parent,
it will silently evaluate to
undefined
. This is done in both the compiled template and the "lookup"-helper.This will prevent new Remote-Code-Execution exploits that have been
published recently.
Compatibility notes:
__proto__
,__defineGetter__
,__defineSetter__
and__lookupGetter__
in the respect that those expression now returnundefined
rather than their actual value from the proto.increase the patch-version, because the incompatible use-cases
are not intended, undocumented and far less important than fixing
Remote-Code-Execution exploits on existing systems.
Commits
v4.5.2
Compare Source
v4.5.1
Compare Source
Bugfixs
5e9d17f
(#1589)Compatibility notes:
Commits
v4.5.0
Compare Source
Features / Improvements
62ed3c2
feb60f8
Bugfixes:
7fcf9d2
Chore:
7052e88
088e618
Compatibility notes:
Commits
v4.4.5
Compare Source
Bugfixes:
8d5530e
, #1579Commits
v4.4.4
Compare Source
Bugfixes:
f1752fe
Chore:
0b593bf
Compatibility notes:
Commits
v4.4.3
Compare Source
Bugfixes
Typings:
0440af2
Commits
v4.4.2
Compare Source
b7eada0
Commits
v4.4.1
Compare Source
Commits
v4.4.0
Compare Source
cf7545e
Commits
v4.3.5
Compare Source
Commits
v4.3.4
Compare Source
ff4d827
Compatibility notes:
Commits
v4.3.3
Compare Source
8742bde
Commits
v4.3.2
Compare Source
213c0bb
, #1563Compatibility notes:
Commits
v4.3.1
Compare Source
Fixes:
1266838
, #156193444c5
,64ecb9e
, #1560Commits
v4.3.0
Compare Source
Fixes:
2078c72
2078c72
Features:
allowCallsToHelperMissing
to allow callingblockHelperMissing
andhelperMissing
.Breaking changes:
Compatibility notes:
Compiler revision increased -
06b7224
The increase was done because the "helperMissing" and "blockHelperMissing" are now moved from the helpers
to the internal "container.hooks" object, so old templates will not be able to call them anymore. We suggest
that you always recompile your templates with the latest compiler in your build pipelines.
Disallow calling "helperMissing" and "blockHelperMissing" directly -
2078c72
{{blockHelperMissing}}
wasnever intended and was part of the exploits that have been revealed early in 20https://github.com/handlebars-lang/handlebars.js/issues/1495s.js/issues/1495). It is also part of a new exploit that
is not captured by the earlier fix. In order to harden Handlebars against such exploits, calling thos helpers
is now not possible anymore. Overriding those helpers is still possible.
allowCallsToHelperMissing
totrue
and thecalls will again be possible
Both bullet points imly that Handlebars is not 100% percent compatible to 4.2.0, despite the minor version bump.
We consider it more important to resolve a major security issue than to maintain 100% compatibility.
Commits
v4.2.2
Compare Source
Commits
v4.2.1
Compare Source
Bugfixes:
c55a7be
, #1553Compatibility notes:
Commits
v4.2.0
Compare Source
Chore/Test:
grunt-saucelab
with current sauce-connect proxy -f119497
f9cce4d
a57b682
Bugfixes:
knownHelpers
doesnt allow for custom helpers (@NickCis)Features:
Compatibility notes:
shows that it works, but if it doesn't please open an issue.
Commits
v4.1.2
Compare Source
#1540 - added browser to package.json, resolves #1102 (@ouijan)
Compatibility notes:
Commits
v4.1.1
Compare Source
Bugfixes:
5cedd62
Refactorings:
048f2ce
445ae12
Compatibility notes:
Commits
v4.1.0
Compare Source
New Features
27ac1ee
Security fixes:
42841c4
, #1495Housekeeping
bacd473
78dd89c
6b87c21
Compatibility notes:
Access to class constructors (i.e.
({}).constructor
) is now prohibited to preventRemote Code Execution. This means that following construct will no work anymore:
This kind of access is not the intended use of Handlebars and leads to the vulnerability described in #1495. We will not increase the major version, because such use is not intended or documented, and because of the potential impact of the issue (we fear that most people won't use a new major version and the issue may not be resolved on many systems).
Commits
v4.0.14
Compare Source
v4.0.13
Compare Source
v4.0.12
Compare Source
New features:
Various dependency updates
d3d3942
7729aa9
73d5637
)Bugfixes:
source-map
-package should work better withrollup
#1463Removed obsolete code:
0ddff8b
files
field -69c6ca5
8947dd0
Compatibility notes:
Commits
v4.0.11
Compare Source
uglify-js
is unconditionally imported, but only listed as optional dependency (@Turbo87)21386b6
Compatibility notes:
Commits