Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security] Bump handlebars from 4.1.2 to 4.5.3 #3818

Merged
merged 1 commit into from
Jan 6, 2020

Conversation

dependabot-preview[bot]
Copy link
Contributor

@dependabot-preview dependabot-preview bot commented Dec 26, 2019

Bumps handlebars from 4.1.2 to 4.5.3. This update includes a security fix.

Vulnerabilities fixed

Sourced from The GitHub Security Advisory Database.

High severity vulnerability that affects handlebars Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's proto and defineGetter properties, which may allow an attacker to execute arbitrary code through crafted payloads.

Affected versions: < 4.3.0

Changelog

Sourced from handlebars's changelog.

v4.5.3 - November 18th, 2019

Bugfixes:

  • fix: add "no-prototype-builtins" eslint-rule and fix all occurences - f7f05d7
  • fix: add more properties required to be enumerable - 1988878

Chores / Build:

  • fix: use !== 0 instead of != 0 - c02b05f
  • add chai and dirty-chai and sinon, for cleaner test-assertions and spies, deprecate old assertion-methods - 93e284e, 886ba86, 0817dad, 93516a0

Security:

  • The properties __proto__, __defineGetter__, __defineSetter__ and __lookupGetter__ have been added to the list of "properties that must be enumerable". If a property by that name is found and not enumerable on its parent, it will silently evaluate to undefined. This is done in both the compiled template and the "lookup"-helper. This will prevent new Remote-Code-Execution exploits that have been published recently.

Compatibility notes:

  • Due to the security-fixes. The semantics of the templates using __proto__, __defineGetter__, __defineSetter__ and __lookupGetter__ in the respect that those expression now return undefined rather than their actual value from the proto.
  • The semantics have not changed in cases where the properties are enumerable, as in:
{
  __proto__: 'some string'
}
  • The change may be breaking in that respect, but we still only increase the patch-version, because the incompatible use-cases are not intended, undocumented and far less important than fixing Remote-Code-Execution exploits on existing systems.

Commits

v4.5.2 - November 13th, 2019

Bugfixes

  • fix: use String(field) in lookup when checking for "constructor" - d541378
  • test: add fluent API for testing Handlebars - c2ac79c

Compatibility notes:

  • no incompatibility are to be expected
... (truncated)
Commits
  • c819c8b v4.5.3
  • 827c9d0 Update release notes
  • f7f05d7 fix: add "no-prototype-builtins" eslint-rule and fix all occurences
  • 1988878 fix: add more properties required to be enumerable
  • 886ba86 test/chore: add chai/expect and sinon to "runtime"-environment
  • 0817dad test: add sinon as global variable to eslint in the specs
  • 93516a0 test: add sinon.js for spies, deprecate current assertions
  • 93e284e chore: add chai and dirty-chai for better test assertions
  • c02b05f fix: use !== 0 instead of != 0
  • 8de121d v4.5.2
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in your Dependabot dashboard:

  • Update frequency (including time of day and day of week)
  • Pull request limits (per update run and/or open at any time)
  • Automerge options (never/patch/minor, and dev/runtime dependencies)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)
Microsoft Reviewers: Open in CodeFlow

Bumps [handlebars](https://github.com/wycats/handlebars.js) from 4.1.2 to 4.5.3. **This update includes a security fix.**
- [Release notes](https://github.com/wycats/handlebars.js/releases)
- [Changelog](https://github.com/wycats/handlebars.js/blob/master/release-notes.md)
- [Commits](handlebars-lang/handlebars.js@v4.1.2...v4.5.3)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
@dependabot-preview dependabot-preview bot requested a review from a team as a code owner December 26, 2019 18:32
@dependabot-preview dependabot-preview bot added dependencies Pull requests that update a dependency file security Pull requests that address a security vulnerability labels Dec 26, 2019
@acoates-ms acoates-ms merged commit 832d811 into master Jan 6, 2020
@dependabot-preview dependabot-preview bot deleted the dependabot/npm_and_yarn/handlebars-4.5.3 branch January 6, 2020 17:34
ghost pushed a commit that referenced this pull request Jan 9, 2020
* GetFacebookReactInstance

* def

* ...

* Add __cdecl explicitly

* Update ReactUWP.vcxproj

* Update E2ETest to use ReactApplication (#3715)

* Update E2ETest to use ReactApplication

* Minor update

* Remove generating pch.pch

* Change files

* Shrink pch file size for Microsfot.ReactNative

* Revert "Remove generating pch.pch"

This reverts commit 39286c8.

* fix build

* Update Timeout

* applying package updates ***NO_CI***

* Update ParityStatus.md (#3555)

Documentation update based on #2852 completion

* Bump @microsoft/api-extractor from 7.6.1 to 7.7.0 (#3717)

Bumps [@microsoft/api-extractor](https://github.com/microsoft/rushstack) from 7.6.1 to 7.7.0.
- [Release notes](https://github.com/microsoft/rushstack/releases)
- [Commits](https://github.com/microsoft/rushstack/compare/@microsoft/api-extractor_v7.6.1...@microsoft/api-extractor_v7.7.0)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>

* Bump @microsoft/api-documenter from 7.6.1 to 7.7.2 (#3724)

Bumps [@microsoft/api-documenter](https://github.com/microsoft/rushstack) from 7.6.1 to 7.7.2.
- [Release notes](https://github.com/microsoft/rushstack/releases)
- [Commits](https://github.com/microsoft/rushstack/compare/@microsoft/api-documenter_v7.6.1...@microsoft/api-documenter_v7.7.2)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>

* Aligning Microsoft.Windows.CppWinRT Versions (#3733)

* Re-aligned SampleAppCPP project to match the others, #3728
* Updated all projects to 2.0.190730.2

* applying package updates ***NO_CI***

* Bump @types/react-native from 0.60.22 to 0.60.24 (#3740)

Bumps [@types/react-native](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react-native) from 0.60.22 to 0.60.24.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react-native)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>

* Bump @types/node from 10.17.6 to 10.17.7 (#3741)

Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 10.17.6 to 10.17.7.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>

* Update CONTRIBUTING.md

update instructions on how to install submodules in the case where you started out working on vnext then switched to current.

* Use ReactNative.V8JSI.Windows.0.1.6 and ReactNative.Hermes.Windows.0.1.6 (#3729)

* unify hermes and v8jsi version

* Change files

* use HERMES_Package and V8_Package

* remove them from reactuwp project

* applying package updates ***NO_CI***

* Reduce build time on pipeline (#3734)

* reduce build time

* changes

* fix pipeline failure

* use Add-AppxPackage

* E2E test still use windows-2019 image

* force install vs dependencies on vs2019 image for E2E test

* parameters.forceVSDependencies

* add ../../.ado/variables/vs2017.yml

* Revert "add ../../.ado/variables/vs2017.yml"

This reverts commit b829251.

* revert and force

* Fix pipeline error

* Add react-native-win32 package (#3762)

* Add react-native-win32 package

* Publish packages using access public

* applying package updates ***NO_CI***

* Miscellaneous fixes in ETW tracing and Systrace (#3745)

* Miscellaneous fixes in ETW tracing and Systrace

* Miscellaneous fixes in ETW tracing and Systrace - Adding missing files

* Submitting the ETW schema resouce dll and the register script

* Change files

* applying package updates ***NO_CI***

* Strongly typed value serialization and deserialization using IJSValueReader, JSValue, and IJSValueWriter (#3760)

* Merged implementation of strongly typed value serialization and deserialization using IJSValueReader, JSValue, and IJSValueWriter

* Change files

* Updated CLI template for C++ native modules

* applying package updates ***NO_CI***

* Update to react-native@0.60.0-microsoft.31 (#3769)

* Update to react-native@0.60.0-microsoft.31

* Change files

* Change files

* applying package updates ***NO_CI***

* Fix toggle debugger setting issue with ReactApplication (#3767)

* Fix toggle debugger setting issue with ReactApplication

* applying package updates ***NO_CI***

* Delete .pch after build on pipeline (#3771)

* delete pch after build

* applying package updates ***NO_CI***

* Redirect build directory to C: on vs2017-win2016 build machine (#3768)

* init

* rollback language to default

* use False

* Fix by comment and enable SampleApp on pipeline

* update

* disable msbuild SampleApp

* Apply suggestions from code review

* applying package updates ***NO_CI***

* ignore Bundle folder in sampleapps (#3778)

* Add tree dump utility to E2E test framework and fix Image border issue (#3754)

Add TreeDump utility to E2E test framework and image border fix with TreeDump tests.

* applying package updates ***NO_CI***

* Update yarn.lock

* Change files

* Added new unit test projects to ReactWindows-Universal solution. (#3775)

* Added new unit test projects to ReactWindows-Universal solution.

* Made C# code compatible with C# 7.0

* Fixed some build breaks found by CI

* Trying to fix the Microsoft.ReactNative.Cxx.UnitTests build in CI loop

* Fixed Microsoft.ReactNative.Cxx.UnitTests project build break in CI and removed AMD64.

* Removed C# unit tests project

* applying package updates ***NO_CI***

* Update document for removing ReleaseBundle and DebugBundle (#3702)

* Update doc to removing DebugBundle and ReleaseBundle

* Change files

* applying package updates ***NO_CI***

* CLI reads name from app.json if it doesn't exist in package.json (#3781)

* read name from app.json

* Change files

* applying package updates ***NO_CI***

* Change CLI to add prompt if no --template parameter is supplied (#3784)

* merge

* add prompt

* Change files

* applying package updates ***NO_CI***

* Conditionally use BitmapImage (#3712)

* Use BitmapImage for cover, contain, and stretch resizeModes

* Fix comments

* timing issues

* wip

* Move 'center' resizeMode to BitmapImage

* code cleanup

* ReactImage->Source() refactor

* Clean up for PR

* Change files

* PR feedback

* only create ImageBrush and BitmapImage is needed

* Remove memory stream cache + flicker workaround

* don't cache availablesize + formatting

* SizeChanged event handler

* Fix dynamic resizeMode switch edge case

* Fix merge conflict + add inline data to image playground

* fix playground buildci

* applying package updates ***NO_CI***

* Bump rnpm-plugin-windows from 0.3.8 to 0.4.0 (#3800)

Bumps [rnpm-plugin-windows](https://github.com/ReactWindows/react-native-windows) from 0.3.8 to 0.4.0.
- [Release notes](https://github.com/ReactWindows/react-native-windows/releases)
- [Commits](rnpm-plugin-windows_v0.3.8...rnpm-plugin-windows_v0.4.0)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>

* Bump pretty-format from 24.8.0 to 24.9.0 (#3764)

Bumps [pretty-format](https://github.com/facebook/jest/tree/HEAD/packages/pretty-format) from 24.8.0 to 24.9.0.
- [Release notes](https://github.com/facebook/jest/releases)
- [Changelog](https://github.com/facebook/jest/blob/master/CHANGELOG.md)
- [Commits](https://github.com/facebook/jest/commits/v24.9.0/packages/pretty-format)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>

* Bump stacktrace-parser from 0.1.6 to 0.1.8 (#3765)

Bumps [stacktrace-parser](https://github.com/errwischt/stacktrace-parser) from 0.1.6 to 0.1.8.
- [Release notes](https://github.com/errwischt/stacktrace-parser/releases)
- [Commits](https://github.com/errwischt/stacktrace-parser/commits)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>

* Bump @types/react-native from 0.60.24 to 0.60.25 (#3757)

Bumps [@types/react-native](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react-native) from 0.60.24 to 0.60.25.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react-native)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>

* Port windowsbrush code into react-native-windows (#3789)

* merge

* move windowsBrush stuff over from fork

* added RNTester page

* Change files

* CR comments

* applying package updates ***NO_CI***

* Make sure that C# and C++ SampleApp projects identifiers have proper CS and Cpp suffixes to avoid name collisions. (#3802)

* Removed Bridge sub-namespace in favor of Microsoft.ReactNative (#3804)

* Removed Bridge sub-namespace in favor of Microsoft.ReactNative

* Change files

* Fixed E2ETest build break

* applying package updates ***NO_CI***

* fixing case issues (#3806)

* Bump @react-native-community/cli from 2.9.0 to 2.10.0 (#3663)

Bumps [@react-native-community/cli](https://github.com/react-native-community/react-native-cli) from 2.9.0 to 2.10.0.
- [Release notes](https://github.com/react-native-community/react-native-cli/releases)
- [Commits](react-native-community/cli@v2.9.0...v2.10.0)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>

* reduce build flavors for RNWUniversalPR  (#3773)

* reduce build flavours

* reenable DesktopPR

* \\

* Update .ado/windows-vs-pr.yml

* Bunch of style properties fixes and TreeDump utility updates (#3793)

* Support CornerRadius for TextInput

* Fix cornerRadius issue for TextInput and some updates to TreeDump, plus new test for control style.

* applying package updates ***NO_CI***

* Get flow clean, and turn on flow-check during build (#3730)

* Get flow check working

* Get flow clean, and turn on flow check during build

* Change files

* fix

* Move RNTester files to matching location from RN\rntester

* PR feedback

* fix

* applying package updates ***NO_CI***

* SourceCode module should provide scriptURL when running livereload without webdebugger (#3803)

* Minor fixups after initial rn-win32 checkin

* Provide source uri in SourceCode module when using livereload

* Provide source uri in SourceCode module when using livereload

* Change files

* build fix

* fix build

* fix build

* applying package updates ***NO_CI***

* Remove remaining need for fork of RN for win32 JS (#3811)

* Remove remaining need for fork of RN for win32 JS

* Change files

* Build fix

* Change files

* applying package updates ***NO_CI***

* Export ability to query names of loaded native modules (master branch) (#3813)

* Export ability to query native module names

This is needed for testability (intenral CR using it out now). It's not ideal to add more exports, but we will always have to have some between instance interfaces.

* Change files

* Fix x86 mangeled name

* applying package updates ***NO_CI***

* Changed Microsoft.ReactNative to be independent from ReactUWP (#3809)

* Changed Microsoft.ReactNative to be independent from ReactUWP

* Removed ReactUWP project from the ReactUWPTestApp to reduce compiled code size.

* Removed commented code from pch.h

* Moved WindowsBrushExample.windows.tsx to fix RNTester bundle building

* Updated TreeDumps to fix test cases.

* An attempt to fix E2ETest

* Changed ViewPanel naemspace in the E2ETest tree dumps

* Changed namespace for ViewPanel in other E2ETest tree dumps

* applying package updates ***NO_CI***

* Allow UAP SDK to be in other folder other than ProgramFiles (#3815)

* check UAP in SDK10 installation folder

* applying package updates ***NO_CI***

* Add InjectBundleContent target (#3821)

* add InjectBundleContent target

* Change files

* format

* applying package updates ***NO_CI***

* Bump @types/react-native from 0.60.25 to 0.60.28 (#3831)

Bumps [@types/react-native](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react-native) from 0.60.25 to 0.60.28.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react-native)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>

* [Security] Bump handlebars from 4.1.2 to 4.5.3 (#3818)

Bumps [handlebars](https://github.com/wycats/handlebars.js) from 4.1.2 to 4.5.3. **This update includes a security fix.**
- [Release notes](https://github.com/wycats/handlebars.js/releases)
- [Changelog](https://github.com/wycats/handlebars.js/blob/master/release-notes.md)
- [Commits](handlebars-lang/handlebars.js@v4.1.2...v4.5.3)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>

* Call StartAnimation on m_scaleCombined for ScaleX / ScaleY animations (#3829)

* Call StartAnimatiom on m_scaleCombined for ScaleX / ScaleY animations

There was a copy-paste error previously that started m_translationCombined instead.

* Change files

* applying package updates ***NO_CI***

* Remove remaining need for fork of RN for win32 JS (#3834)

* Remove remaining need for fork of RN for win32 JS

* Change files

* Build fix

* Change files

* Enable flow type checking in win32

* Fix build

* applying package updates ***NO_CI***

* Rename GetFacebookReactInstance

* Fix code review comment

* Update TurboModuleUtils.cpp

* Fix lint errors

Co-authored-by: Di Da <dida@microsoft.com>
Co-authored-by: rnbot <53619745+rnbot@users.noreply.github.com>
Co-authored-by: Harini Kannan <harinik@microsoft.com>
Co-authored-by: dependabot-preview[bot] <27856297+dependabot-preview[bot]@users.noreply.github.com>
Co-authored-by: Jon Thysell <thysell@gmail.com>
Co-authored-by: kmelmon <33470154+kmelmon@users.noreply.github.com>
Co-authored-by: Canhua Li <canli@microsoft.com>
Co-authored-by: Andrew Coates <30809111+acoates-ms@users.noreply.github.com>
Co-authored-by: Anandraj <mganandraj@outlook.com>
Co-authored-by: Vladimir Morozov <vmoroz@users.noreply.github.com>
Co-authored-by: Marlene Cota <marlenecota@gmail.com>
Co-authored-by: Mike Kaufman <mike-kaufman@users.noreply.github.com>
Co-authored-by: Nick Gerleman <nick@nickgerleman.com>
Co-authored-by: Tom Shea <tom@shea.at>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file security Pull requests that address a security vulnerability
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant