An in-range update of dot is breaking the build 🚨
- Langage dominant
- Aucune donnée de langage
- Étoiles
- 3
- Forks
- 1
- Métriques de merge des PR
- Aucune PR mergée en 30 j
Description
## The dependency [dot](https://github.com/olado/doT) was updated from `1.1.2` to `1.1.3`.
🚨 [View failing branch](https://github.com/aethant/merino/compare/master...aethant:greenkeeper%2Fdot-1.1.3).
This version is **covered** by your **current version range** and after updating it in your project **the build failed**.
dot is a direct dependency of this project, and **it is very likely causing it to break**. If other packages depend on yours, this update is probably also breaking those in turn.
Status Details
- ❌ **continuous-integration/travis-ci/push:** The Travis CI build failed ([Details](https://travis-ci.org/aethant/merino/builds/622037251?utm_source=github_status&utm_medium=notification)).
---
Release Notes for v1.1.3
Tests for doT.process
Patch code injection via prototype pollution (#291)
Commits
The new version differs by 12 commits.
6adbd81docs: noted00300e1.1.387ccef3test: update travis versions4cc3253chore: update dependencies320e847test: missing test filesef5f353docs: security considerationsc531369test: exclude unused code from coverageb4fd211test: doT.processfa3890dtest: use doT required via the main module2cf2226fix: prevent possibility of execution of the code injected via prototype pollution when undefined is passed to compiled template function, closes #291299b4daMerge pull request #237 from EdwardBetts/spelling2dfe1afcorrect spelling mistake
See the full diff
FAQ and help
There is a collection of [frequently asked questions](https://greenkeeper.io/faq.html). If those don’t help, you can always [ask the humans behind Greenkeeper](https://github.com/greenkeeperio/greenkeeper/issues/new).
---
Your [Greenkeeper](https://greenkeeper.io) Bot :palm_tree:
Guide de contribution
Aucun guide de contribution indexé pour ce dépôt
Évaluation
Cette issue n'a pas encore été évaluée.