Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

update to latest jstransformers-pug@0.4.0 due to security issue with pug@<3.0.1 #175

Closed
jwhaney opened this issue Mar 9, 2021 · 0 comments · Fixed by #177
Closed

update to latest jstransformers-pug@0.4.0 due to security issue with pug@<3.0.1 #175

jwhaney opened this issue Mar 9, 2021 · 0 comments · Fixed by #177

Comments

@jwhaney
Copy link

jwhaney commented Mar 9, 2021

this is just a heads up to update to the latest version of jstransformers-pug when possible. jstransformers-pug relied on the older version of pug@2.0 which had a high severity security vulnerability (see below). now it is updated to latest version @3.0.2.

github high severity notification:
image

new jstransformers-pug@0.4.0 version:
https://www.npmjs.com/package/jstransformer-pug

cheers

@ismay ismay closed this as completed in #177 Mar 9, 2021
@jwhaney jwhaney changed the title update to latest jstransformers-pug@0.4.0 due to security issue with pug@>3.0.1 update to latest jstransformers-pug@0.4.0 due to security issue with pug@<3.0.1 Mar 9, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant