[Snyk] Upgrade nunjucks from 3.0.1 to 3.2.3 #5
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade nunjucks from 3.0.1 to 3.2.3.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version fixes:
SNYK-JS-NUNJUCKS-1079083
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-GLOBPARENT-1016905
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
npm:braces:20180219
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
(*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: nunjucks
select
andreject
filters. Merge of #1278 and #1279; fixes #282. Thanks ogonkov!TypeError: name.replace is not a function
. Fixes #1295.groupby
filter; respectthrowOnUndefined
option, if the groupby attribute is undefined. Merge of #1276; fixes #1198. Thanks ogonkov!indent
filter no longer appends an additional newline. Fixes #1231.^2.0.0
to^3.3.0
. Merge of #1254. Thanks eklingen.NodeResolveLoader
, a Loader that loads templates using node'srequire.resolve
. Fixes #1175.Environment
instances, to allow runtime dependency tracking. Fixes #1153.Fix bug where exceptions were silently swallowed with synchronous render. Fixes #678, #1116, #1127, and #1164
Removes deprecated postinstall-build package in favor of npm prepare. Merge of #1172. Fixes #1167.
No changes from 3.1.5; fixed packaging issue in npm
Add
forceescape
filter. Fixes #782Fix regression that prevented template errors from reporting line and column number. Fixes #1087 and #1095.
Fix "Invalid type: Is" error for
{% if value is defined %}
. Fixes #1110Formally drop support for node v4 (the upgrade to babel 7 in v3.1.0 made the build process incompatible with node < 6.9.0).
Fix postinstall-build packaging issue, v3.1.2
Commit messages
Package name: nunjucks
Compare
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
🧐 View latest project report
🛠 Adjust upgrade PR settings
🔕 Ignore this dependency or unsubscribe from future upgrade PRs