core icon indicating copy to clipboard operation
core copied to clipboard

moustache vulnerability

Open joneit opened this issue 8 years ago • 3 comments

GitHub informed us that [email protected] has a security vulnerability.

We will update to [email protected] on our next release.

I have already made the edit to package.json in my 3.0.0 branch (was "2.2.0"; now "^2.3.0"). There is little point in pushing this change separately without also releasing new build files to npm and the CDN.

@dcchuck and @Dwaynekj If you guys feel it is urgent, we could do an interim release before 3.0.0.

joneit avatar Nov 28 '17 17:11 joneit

I'm ok with a hotfix to master

Dwaynekj avatar Nov 28 '17 23:11 Dwaynekj

@joneit ?

Dwaynekj avatar Dec 01 '17 16:12 Dwaynekj

@joneit ?

Dwaynekj avatar Dec 10 '17 15:12 Dwaynekj