Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability issue reported in hbs package #1599

Closed
sanjeev3094 opened this issue Sep 30, 2021 · 6 comments · Fixed by #1659
Closed

Vulnerability issue reported in hbs package #1599

sanjeev3094 opened this issue Sep 30, 2021 · 6 comments · Fixed by #1659
Labels

Comments

@sanjeev3094
Copy link

Vulnerability issue reported in hbs package: GHSA-7f5c-rpf4-86p8.
I tried to open an issue in hbs github repo but it got closed and not showing up.
Is there possibilty to move to some other alternate package.

Thanks

@welcome
Copy link

welcome bot commented Sep 30, 2021

Thanks for opening this issue. A contributor should be by to give feedback soon. In the meantime, please check out the contributing guidelines and explore other ways you can get involved.

@AaronDewes
Copy link
Member

While this is a vulnerability,it doesn't seem to affect Probot, does it?

@gr2m
Copy link
Contributor

gr2m commented Sep 30, 2021

I'm not sure. We do use the hbs middleware for the /probot endpoint, so if you use the probot server your app might be affected. I don't have the time to look into it in more detail myself right now, the CVE is not very detailed

@aasiddiq
Copy link
Contributor

aasiddiq commented Mar 3, 2022

Checking in to see if there are any plans to move away from hbs since there has been no response from them about the vulnerability.

@aasiddiq
Copy link
Contributor

aasiddiq commented Mar 3, 2022

@gr2m I have created #1659 to replace hbs with express-handlebars. Could have a look in this?
If all is good can we plan for a release for this soon? It will help us meet the project fundamental guidelines.

@gr2m gr2m closed this as completed in #1659 Mar 8, 2022
@github-actions
Copy link

github-actions bot commented Mar 8, 2022

🎉 This issue has been resolved in version 12.2.2 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants