-
Notifications
You must be signed in to change notification settings - Fork 1.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Security] Bump handlebars from 4.1.2 to 4.5.3 #3818
Merged
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Bumps [handlebars](https://github.com/wycats/handlebars.js) from 4.1.2 to 4.5.3. **This update includes a security fix.** - [Release notes](https://github.com/wycats/handlebars.js/releases) - [Changelog](https://github.com/wycats/handlebars.js/blob/master/release-notes.md) - [Commits](handlebars-lang/handlebars.js@v4.1.2...v4.5.3) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
dependabot-preview
bot
added
dependencies
Pull requests that update a dependency file
security
Pull requests that address a security vulnerability
labels
Dec 26, 2019
acoates-ms
approved these changes
Jan 6, 2020
dependabot-preview
bot
deleted the
dependabot/npm_and_yarn/handlebars-4.5.3
branch
January 6, 2020 17:34
ghost
pushed a commit
that referenced
this pull request
Jan 9, 2020
* GetFacebookReactInstance * def * ... * Add __cdecl explicitly * Update ReactUWP.vcxproj * Update E2ETest to use ReactApplication (#3715) * Update E2ETest to use ReactApplication * Minor update * Remove generating pch.pch * Change files * Shrink pch file size for Microsfot.ReactNative * Revert "Remove generating pch.pch" This reverts commit 39286c8. * fix build * Update Timeout * applying package updates ***NO_CI*** * Update ParityStatus.md (#3555) Documentation update based on #2852 completion * Bump @microsoft/api-extractor from 7.6.1 to 7.7.0 (#3717) Bumps [@microsoft/api-extractor](https://github.com/microsoft/rushstack) from 7.6.1 to 7.7.0. - [Release notes](https://github.com/microsoft/rushstack/releases) - [Commits](https://github.com/microsoft/rushstack/compare/@microsoft/api-extractor_v7.6.1...@microsoft/api-extractor_v7.7.0) Signed-off-by: dependabot-preview[bot] <support@dependabot.com> * Bump @microsoft/api-documenter from 7.6.1 to 7.7.2 (#3724) Bumps [@microsoft/api-documenter](https://github.com/microsoft/rushstack) from 7.6.1 to 7.7.2. - [Release notes](https://github.com/microsoft/rushstack/releases) - [Commits](https://github.com/microsoft/rushstack/compare/@microsoft/api-documenter_v7.6.1...@microsoft/api-documenter_v7.7.2) Signed-off-by: dependabot-preview[bot] <support@dependabot.com> * Aligning Microsoft.Windows.CppWinRT Versions (#3733) * Re-aligned SampleAppCPP project to match the others, #3728 * Updated all projects to 2.0.190730.2 * applying package updates ***NO_CI*** * Bump @types/react-native from 0.60.22 to 0.60.24 (#3740) Bumps [@types/react-native](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react-native) from 0.60.22 to 0.60.24. - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react-native) Signed-off-by: dependabot-preview[bot] <support@dependabot.com> * Bump @types/node from 10.17.6 to 10.17.7 (#3741) Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 10.17.6 to 10.17.7. - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) Signed-off-by: dependabot-preview[bot] <support@dependabot.com> * Update CONTRIBUTING.md update instructions on how to install submodules in the case where you started out working on vnext then switched to current. * Use ReactNative.V8JSI.Windows.0.1.6 and ReactNative.Hermes.Windows.0.1.6 (#3729) * unify hermes and v8jsi version * Change files * use HERMES_Package and V8_Package * remove them from reactuwp project * applying package updates ***NO_CI*** * Reduce build time on pipeline (#3734) * reduce build time * changes * fix pipeline failure * use Add-AppxPackage * E2E test still use windows-2019 image * force install vs dependencies on vs2019 image for E2E test * parameters.forceVSDependencies * add ../../.ado/variables/vs2017.yml * Revert "add ../../.ado/variables/vs2017.yml" This reverts commit b829251. * revert and force * Fix pipeline error * Add react-native-win32 package (#3762) * Add react-native-win32 package * Publish packages using access public * applying package updates ***NO_CI*** * Miscellaneous fixes in ETW tracing and Systrace (#3745) * Miscellaneous fixes in ETW tracing and Systrace * Miscellaneous fixes in ETW tracing and Systrace - Adding missing files * Submitting the ETW schema resouce dll and the register script * Change files * applying package updates ***NO_CI*** * Strongly typed value serialization and deserialization using IJSValueReader, JSValue, and IJSValueWriter (#3760) * Merged implementation of strongly typed value serialization and deserialization using IJSValueReader, JSValue, and IJSValueWriter * Change files * Updated CLI template for C++ native modules * applying package updates ***NO_CI*** * Update to react-native@0.60.0-microsoft.31 (#3769) * Update to react-native@0.60.0-microsoft.31 * Change files * Change files * applying package updates ***NO_CI*** * Fix toggle debugger setting issue with ReactApplication (#3767) * Fix toggle debugger setting issue with ReactApplication * applying package updates ***NO_CI*** * Delete .pch after build on pipeline (#3771) * delete pch after build * applying package updates ***NO_CI*** * Redirect build directory to C: on vs2017-win2016 build machine (#3768) * init * rollback language to default * use False * Fix by comment and enable SampleApp on pipeline * update * disable msbuild SampleApp * Apply suggestions from code review * applying package updates ***NO_CI*** * ignore Bundle folder in sampleapps (#3778) * Add tree dump utility to E2E test framework and fix Image border issue (#3754) Add TreeDump utility to E2E test framework and image border fix with TreeDump tests. * applying package updates ***NO_CI*** * Update yarn.lock * Change files * Added new unit test projects to ReactWindows-Universal solution. (#3775) * Added new unit test projects to ReactWindows-Universal solution. * Made C# code compatible with C# 7.0 * Fixed some build breaks found by CI * Trying to fix the Microsoft.ReactNative.Cxx.UnitTests build in CI loop * Fixed Microsoft.ReactNative.Cxx.UnitTests project build break in CI and removed AMD64. * Removed C# unit tests project * applying package updates ***NO_CI*** * Update document for removing ReleaseBundle and DebugBundle (#3702) * Update doc to removing DebugBundle and ReleaseBundle * Change files * applying package updates ***NO_CI*** * CLI reads name from app.json if it doesn't exist in package.json (#3781) * read name from app.json * Change files * applying package updates ***NO_CI*** * Change CLI to add prompt if no --template parameter is supplied (#3784) * merge * add prompt * Change files * applying package updates ***NO_CI*** * Conditionally use BitmapImage (#3712) * Use BitmapImage for cover, contain, and stretch resizeModes * Fix comments * timing issues * wip * Move 'center' resizeMode to BitmapImage * code cleanup * ReactImage->Source() refactor * Clean up for PR * Change files * PR feedback * only create ImageBrush and BitmapImage is needed * Remove memory stream cache + flicker workaround * don't cache availablesize + formatting * SizeChanged event handler * Fix dynamic resizeMode switch edge case * Fix merge conflict + add inline data to image playground * fix playground buildci * applying package updates ***NO_CI*** * Bump rnpm-plugin-windows from 0.3.8 to 0.4.0 (#3800) Bumps [rnpm-plugin-windows](https://github.com/ReactWindows/react-native-windows) from 0.3.8 to 0.4.0. - [Release notes](https://github.com/ReactWindows/react-native-windows/releases) - [Commits](rnpm-plugin-windows_v0.3.8...rnpm-plugin-windows_v0.4.0) Signed-off-by: dependabot-preview[bot] <support@dependabot.com> * Bump pretty-format from 24.8.0 to 24.9.0 (#3764) Bumps [pretty-format](https://github.com/facebook/jest/tree/HEAD/packages/pretty-format) from 24.8.0 to 24.9.0. - [Release notes](https://github.com/facebook/jest/releases) - [Changelog](https://github.com/facebook/jest/blob/master/CHANGELOG.md) - [Commits](https://github.com/facebook/jest/commits/v24.9.0/packages/pretty-format) Signed-off-by: dependabot-preview[bot] <support@dependabot.com> * Bump stacktrace-parser from 0.1.6 to 0.1.8 (#3765) Bumps [stacktrace-parser](https://github.com/errwischt/stacktrace-parser) from 0.1.6 to 0.1.8. - [Release notes](https://github.com/errwischt/stacktrace-parser/releases) - [Commits](https://github.com/errwischt/stacktrace-parser/commits) Signed-off-by: dependabot-preview[bot] <support@dependabot.com> * Bump @types/react-native from 0.60.24 to 0.60.25 (#3757) Bumps [@types/react-native](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react-native) from 0.60.24 to 0.60.25. - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react-native) Signed-off-by: dependabot-preview[bot] <support@dependabot.com> * Port windowsbrush code into react-native-windows (#3789) * merge * move windowsBrush stuff over from fork * added RNTester page * Change files * CR comments * applying package updates ***NO_CI*** * Make sure that C# and C++ SampleApp projects identifiers have proper CS and Cpp suffixes to avoid name collisions. (#3802) * Removed Bridge sub-namespace in favor of Microsoft.ReactNative (#3804) * Removed Bridge sub-namespace in favor of Microsoft.ReactNative * Change files * Fixed E2ETest build break * applying package updates ***NO_CI*** * fixing case issues (#3806) * Bump @react-native-community/cli from 2.9.0 to 2.10.0 (#3663) Bumps [@react-native-community/cli](https://github.com/react-native-community/react-native-cli) from 2.9.0 to 2.10.0. - [Release notes](https://github.com/react-native-community/react-native-cli/releases) - [Commits](react-native-community/cli@v2.9.0...v2.10.0) Signed-off-by: dependabot-preview[bot] <support@dependabot.com> * reduce build flavors for RNWUniversalPR (#3773) * reduce build flavours * reenable DesktopPR * \\ * Update .ado/windows-vs-pr.yml * Bunch of style properties fixes and TreeDump utility updates (#3793) * Support CornerRadius for TextInput * Fix cornerRadius issue for TextInput and some updates to TreeDump, plus new test for control style. * applying package updates ***NO_CI*** * Get flow clean, and turn on flow-check during build (#3730) * Get flow check working * Get flow clean, and turn on flow check during build * Change files * fix * Move RNTester files to matching location from RN\rntester * PR feedback * fix * applying package updates ***NO_CI*** * SourceCode module should provide scriptURL when running livereload without webdebugger (#3803) * Minor fixups after initial rn-win32 checkin * Provide source uri in SourceCode module when using livereload * Provide source uri in SourceCode module when using livereload * Change files * build fix * fix build * fix build * applying package updates ***NO_CI*** * Remove remaining need for fork of RN for win32 JS (#3811) * Remove remaining need for fork of RN for win32 JS * Change files * Build fix * Change files * applying package updates ***NO_CI*** * Export ability to query names of loaded native modules (master branch) (#3813) * Export ability to query native module names This is needed for testability (intenral CR using it out now). It's not ideal to add more exports, but we will always have to have some between instance interfaces. * Change files * Fix x86 mangeled name * applying package updates ***NO_CI*** * Changed Microsoft.ReactNative to be independent from ReactUWP (#3809) * Changed Microsoft.ReactNative to be independent from ReactUWP * Removed ReactUWP project from the ReactUWPTestApp to reduce compiled code size. * Removed commented code from pch.h * Moved WindowsBrushExample.windows.tsx to fix RNTester bundle building * Updated TreeDumps to fix test cases. * An attempt to fix E2ETest * Changed ViewPanel naemspace in the E2ETest tree dumps * Changed namespace for ViewPanel in other E2ETest tree dumps * applying package updates ***NO_CI*** * Allow UAP SDK to be in other folder other than ProgramFiles (#3815) * check UAP in SDK10 installation folder * applying package updates ***NO_CI*** * Add InjectBundleContent target (#3821) * add InjectBundleContent target * Change files * format * applying package updates ***NO_CI*** * Bump @types/react-native from 0.60.25 to 0.60.28 (#3831) Bumps [@types/react-native](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react-native) from 0.60.25 to 0.60.28. - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react-native) Signed-off-by: dependabot-preview[bot] <support@dependabot.com> * [Security] Bump handlebars from 4.1.2 to 4.5.3 (#3818) Bumps [handlebars](https://github.com/wycats/handlebars.js) from 4.1.2 to 4.5.3. **This update includes a security fix.** - [Release notes](https://github.com/wycats/handlebars.js/releases) - [Changelog](https://github.com/wycats/handlebars.js/blob/master/release-notes.md) - [Commits](handlebars-lang/handlebars.js@v4.1.2...v4.5.3) Signed-off-by: dependabot-preview[bot] <support@dependabot.com> * Call StartAnimation on m_scaleCombined for ScaleX / ScaleY animations (#3829) * Call StartAnimatiom on m_scaleCombined for ScaleX / ScaleY animations There was a copy-paste error previously that started m_translationCombined instead. * Change files * applying package updates ***NO_CI*** * Remove remaining need for fork of RN for win32 JS (#3834) * Remove remaining need for fork of RN for win32 JS * Change files * Build fix * Change files * Enable flow type checking in win32 * Fix build * applying package updates ***NO_CI*** * Rename GetFacebookReactInstance * Fix code review comment * Update TurboModuleUtils.cpp * Fix lint errors Co-authored-by: Di Da <dida@microsoft.com> Co-authored-by: rnbot <53619745+rnbot@users.noreply.github.com> Co-authored-by: Harini Kannan <harinik@microsoft.com> Co-authored-by: dependabot-preview[bot] <27856297+dependabot-preview[bot]@users.noreply.github.com> Co-authored-by: Jon Thysell <thysell@gmail.com> Co-authored-by: kmelmon <33470154+kmelmon@users.noreply.github.com> Co-authored-by: Canhua Li <canli@microsoft.com> Co-authored-by: Andrew Coates <30809111+acoates-ms@users.noreply.github.com> Co-authored-by: Anandraj <mganandraj@outlook.com> Co-authored-by: Vladimir Morozov <vmoroz@users.noreply.github.com> Co-authored-by: Marlene Cota <marlenecota@gmail.com> Co-authored-by: Mike Kaufman <mike-kaufman@users.noreply.github.com> Co-authored-by: Nick Gerleman <nick@nickgerleman.com> Co-authored-by: Tom Shea <tom@shea.at>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
dependencies
Pull requests that update a dependency file
security
Pull requests that address a security vulnerability
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps handlebars from 4.1.2 to 4.5.3. This update includes a security fix.
Vulnerabilities fixed
Sourced from The GitHub Security Advisory Database.
Changelog
Sourced from handlebars's changelog.
Commits
c819c8b
v4.5.3827c9d0
Update release notesf7f05d7
fix: add "no-prototype-builtins" eslint-rule and fix all occurences1988878
fix: add more properties required to be enumerable886ba86
test/chore: add chai/expect and sinon to "runtime"-environment0817dad
test: add sinon as global variable to eslint in the specs93516a0
test: add sinon.js for spies, deprecate current assertions93e284e
chore: add chai and dirty-chai for better test assertionsc02b05f
fix: use !== 0 instead of != 08de121d
v4.5.2Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)@dependabot use these labels
will set the current labels as the default for future PRs for this repo and language@dependabot use these reviewers
will set the current reviewers as the default for future PRs for this repo and language@dependabot use these assignees
will set the current assignees as the default for future PRs for this repo and language@dependabot use this milestone
will set the current milestone as the default for future PRs for this repo and language@dependabot badge me
will comment on this PR with code to add a "Dependabot enabled" badge to your readmeAdditionally, you can set the following in your Dependabot dashboard:
Microsoft Reviewers: Open in CodeFlow