mirror of
https://github.com/discourse/discourse.git
synced 2024-12-14 01:38:24 +08:00
39bececaaf
WS-2019-0064: Versions of handlebars prior to 4.0.14 are vulnerable to Prototype Pollution. Templates may alter an Objects prototype, thus allowing an attacker to execute arbitrary code on the server.
51 lines
1.7 KiB
JSON
51 lines
1.7 KiB
JSON
{
|
|
"name": "discourse",
|
|
"version": "1.0.0",
|
|
"main": "index.js",
|
|
"repository": "git@github.com:discourse/discourse.git",
|
|
"author": "Discourse",
|
|
"license": "MIT",
|
|
"dependencies": {
|
|
"@fortawesome/fontawesome-free": "5.7.2",
|
|
"ace-builds": "1.4.2",
|
|
"bootbox": "3.2.0",
|
|
"bootstrap": "v3.4.1",
|
|
"chart.js": "2.7.3",
|
|
"favcount": "https://github.com/chrishunt/favcount",
|
|
"handlebars": "^4.1.2",
|
|
"highlight.js": "https://github.com/highlightjs/highlight.js",
|
|
"htmlparser": "https://github.com/tautologistics/node-htmlparser",
|
|
"intersection-observer": "^0.5.1",
|
|
"jquery": "3.4.1",
|
|
"jquery-color": "1.0.0",
|
|
"jquery-resize": "https://github.com/cowboy/jquery-resize/",
|
|
"jquery-tags-input": "1.3.5",
|
|
"jquery.autoellipsis": "https://github.com/pvdspek/jquery.autoellipsis",
|
|
"jquery.cookie": "1.4.1",
|
|
"magnific-popup": "1.1.0",
|
|
"markdown-it": "8.4.1",
|
|
"moment": "2.24.0",
|
|
"moment-timezone": "0.5.25",
|
|
"moment-timezone-names-translations": "https://github.com/discourse/moment-timezone-names-translations",
|
|
"mousetrap": "https://github.com/discourse/mousetrap#firefox-alt-key",
|
|
"pikaday": "1.8.0",
|
|
"resumablejs": "1.1.0",
|
|
"spectrum-colorpicker": "1.8.0"
|
|
},
|
|
"devDependencies": {
|
|
"babel-eslint": "^8.2",
|
|
"chrome-launcher": "^0.10",
|
|
"chrome-remote-interface": "^0.25",
|
|
"eslint": "^4.19",
|
|
"pretender": "^1.6",
|
|
"prettier": "^1.16.4",
|
|
"puppeteer": "1.16",
|
|
"qunit": "2.8.0",
|
|
"route-recognizer": "^0.3.3",
|
|
"sinon": "^7.2.5"
|
|
},
|
|
"scripts": {
|
|
"preinstall": "node -e \"if(process.env.npm_execpath.indexOf('yarn') === -1) throw new Error('NPM is not supported, please use Yarn instead. ')\""
|
|
}
|
|
}
|