Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update underscore version to avoid security vulnerabilities #61

Merged
merged 1 commit into from Apr 27, 2021

Conversation

ttc229
Copy link
Contributor

@ttc229 ttc229 commented Apr 26, 2021

Our project flagged a Security Vulnerability in the underscore dependency jashkenas/underscore#2915 which is hoisted via spritesheet-templates.

The current package.json uses "underscore": "~1.4.2". The fix for the underscore vulnerability is in versions 1.12.1,1.13.0-2.

Our project flagged a Security Vulnerability in the underscore dependency jashkenas/underscore#2915 which is hoisted via spritesheet-templates.

The current package.json uses "underscore": "~1.4.2". The fix for the underscore vulnerability is in versions 1.12.1,1.13.0-2.
@twolfson
Copy link
Owner

👍 Looks good, should be able to land tonight

@twolfson
Copy link
Owner

Unsure why CI didn't run but tests pass locally. Landing now + releasing

@twolfson twolfson merged commit 068119c into twolfson:master Apr 27, 2021
@twolfson
Copy link
Owner

twolfson commented Apr 27, 2021

This has released in 10.5.1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants