Commit Graph

1736 Commits

Author SHA1 Message Date
Nils Knappmeier 40fb115e53 Revert "chore: re-activate saucelabs"
This reverts commit b2e2cfe56d.
2019-02-19 10:49:24 +01:00
Nils Knappmeier b2e2cfe56d chore: re-activate saucelabs 2019-02-19 10:31:42 +01:00
Nils Knappmeier 037bfbf4d9 Merge pull request #1500 from wycats/neo-async
Use `neo-async` instead of `async
2019-02-19 09:49:49 +01:00
Nils Knappmeier 048f2ce7d2 refactor: replace "async" with "neo-async"
The main reason is that neo-async takes a lot less space due to the missing lodash-dependency.
The other is speed.

closes #1431
2019-02-18 19:26:38 +01:00
Nils Knappmeier b92589a3b0 test: add test for NodeJS compatibility
The test is a simple addition to the existing tests. It should ensure
that the built Handlebars artifact only uses language features that are
available in old versions of NodeJS. A simple program and the
precompiler are started with NodeJS 0.10 to 11
2019-02-18 19:20:39 +01:00
Nils Knappmeier 1c62d4c5d0 Merge branch 'issue-1495' into 4.x 2019-02-07 11:03:35 +01:00
Nils Knappmeier 7caca944b1 v4.1.0 v4.1.0 2019-02-07 10:46:32 +01:00
Nils Knappmeier 7bd34fb466 Update release notes 2019-02-07 10:46:01 +01:00
Nils Knappmeier b02e9a25ee test: run appveyor tests in Node 10 2019-02-07 10:19:53 +01:00
Nils Knappmeier f1c8b2e2a2 chore: disable sauce-labs
Related to #1497
2019-02-07 10:19:53 +01:00
Nils Knappmeier dbc50ac705 chore: bump version of grunt-saucelabs 2019-02-07 10:19:53 +01:00
Nils Knappmeier c6a8fc1c04 chore: add .idea and yarn-error.log to .gitignore 2019-02-07 10:19:53 +01:00
Nils Knappmeier 42841c41a4 fix: disallow access to the constructor in templates to prevent RCE
This commit fixes a Remote Code Execution (RCE) reported by
npm-security. Access to non-enumerable "constructor"-properties
is now prohibited by the compiled template-code, because this
the first step on the way to creating and execution arbitrary
JavaScript code.
The vulnerability affects systems where an attacker is allowed to
inject templates into the Handlebars setup.
Further details of the attack may be disclosed by npm-security.

Closes #1267
Closes #1495
2019-02-07 10:19:53 +01:00
Nils Knappmeier 56fc6768d1 test: run appveyor tests in Node 10 2019-02-07 10:14:44 +01:00
Nils Knappmeier ee3022228b chore: disable sauce-labs
Related to #1497
2019-02-07 10:04:17 +01:00
Nils Knappmeier 05e6293bb3 chore: bump version of grunt-saucelabs 2019-02-07 09:53:09 +01:00
Nils Knappmeier 2db0d123c8 chore: add .idea and yarn-error.log to .gitignore 2019-02-07 08:49:52 +01:00
Nils Knappmeier edc6220d51 fix: disallow access to the constructor in templates to prevent RCE
This commit fixes a Remote Code Execution (RCE) reported by
npm-security. Access to non-enumerable "constructor"-properties
is now prohibited by the compiled template-code, because this
the first step on the way to creating and execution arbitrary
JavaScript code.
The vulnerability affects systems where an attacker is allowed to
inject templates into the Handlebars setup.
Further details of the attack may be disclosed by npm-security.

Closes #1267
Closes #1495
2019-02-07 08:49:41 +01:00
Nils Knappmeier bacd473fe6 chore: fix components/handlebars package.json and auto-update on release 2019-01-02 01:07:05 +01:00
Timothy Lindvall 27ac1ee396 Feat: Import TypeScript typings
- Import typings from DefinitelyTyped into repo.
- Update typings header to cite contributors from history and git blame.
- Update package.json to add typings field.
2018-12-21 23:27:58 +01:00
Nils Knappmeier 78dd89c13a chore: Use node 10 to build handlebars
Node 10 is LTS now...
2018-12-15 23:40:08 +01:00
Nils Knappmeier 6b87c21fc4 chore/doc: Add more release docs 2018-12-15 23:37:40 +01:00
Nils Knappmeier 8d22e6f501 v4.0.12 v4.0.12 2018-09-04 20:44:38 +02:00
Nils Knappmeier 3c970cc9c1 Update release notes 2018-09-04 20:44:07 +02:00
Nils Knappmeier abba3c7526 Update release notes 2018-09-04 20:37:53 +02:00
Nils Knappmeier 4bf1c4ff66 Update release notes 2018-09-04 20:36:06 +02:00
Nils Knappmeier 41b6a11d11 Merge branch '4.x' of github.com:wycats/handlebars.js into 4.x 2018-09-04 20:08:57 +02:00
Nils Knappmeier 2d28f920b0 bump grunt-plugin-dependencies to 1.x versions 2018-09-04 18:53:01 +02:00
Nils Knappmeier 29b174468d style: omit linting error caused by removing "if" 2018-09-04 18:53:01 +02:00
Nils Knappmeier d130ed2bc1 chore: bump various dependencies
- grunt -> 1
- grunt-contrib-watch -> 1
- mocha -> 5
  - in common.js: define "global" , see mochajs/mocha#1159
  - in builtins.js: revert "console.log" to old value just
    after using the mock (in log-helper tests), because
    mocha calls "console.log" on failure, before
    "afterEach"
2018-09-04 18:53:01 +02:00
Nils Knappmeier 2145c14994 bump grunt-plugin-dependencies to 1.x versions 2018-09-04 00:18:46 +02:00
Nils Knappmeier 8359722e5d style: omit linting error caused by removing "if" 2018-09-04 00:16:01 +02:00
Nils Knappmeier a1d864d4a7 chore: bump various dependencies
- grunt -> 1
- grunt-contrib-watch -> 1
- mocha -> 5
  - in common.js: define "global" , see mochajs/mocha#1159
  - in builtins.js: revert "console.log" to old value just
    after using the mock (in log-helper tests), because
    mocha calls "console.log" on failure, before
    "afterEach"
2018-09-04 00:15:02 +02:00
Qiang Li 0ddff8b388 unnecessary check
(cherry picked from commit e1fa310)
2018-05-31 23:16:26 +02:00
Nils Knappmeier 288e986161 Docs: Document branches in the CONTRIBUTING guide 2018-05-31 23:15:24 +02:00
Nils Knappmeier 30df8a1ac7 Testcase for accessing @root from a partial-block
related to #1445
2018-05-31 23:12:08 +02:00
Nils Knappmeier cda544bca9 Add package.json to components shim
This is an attempt to provide a valid package.json-file to the shim
repository for bower, in order to support `bower-away`

see components/handlebars.js#24
2017-11-28 22:13:17 +01:00
aaharu 69c6ca528d Use files field 2017-11-26 02:08:20 +09:00
Nils Knappmeier a4e39bdfd0 Fix release-notes (links to contributors` pages) 2017-11-09 10:46:39 +01:00
Nils Knappmeier b86b9189fa Fix release-notes (links to github-repo) 2017-11-09 10:44:20 +01:00
tim d3d39423a3 upgrade uglify-js 2017-10-21 23:04:23 +02:00
Nils Knappmeier 73d5637564 Update dependencies "async" to 2.5.0 and "source-map" to 0.6.1 2017-10-21 16:09:33 +02:00
Nils Knappmeier 7729aa956b Update grunt-eslint to 20.1.0 2017-10-21 15:42:27 +02:00
Nils Knappmeier 8947dd077c Update jsfiddle to 4.0.11 2017-10-17 23:15:53 +02:00
Nils Knappmeier 1e954ddf3c v4.0.11 v4.0.11 2017-10-17 22:52:25 +02:00
Nils Knappmeier 1ac131e652 Update release notes 2017-10-17 22:51:42 +02:00
Nils Knappmeier 59548b4bdc Extend compiler-api example by replacing child-compiler
closes #1376

(cherry picked from commit ce3cd8a)
2017-10-17 22:30:31 +02:00
Marcos Marado 21386b6474 Update (C) year in the LICENSE file
Welcome to 2017!

(cherry picked from commit 33773c2)
2017-10-17 22:21:41 +02:00
Nils Knappmeier 79309659e1 Gracefully handle missing uglify-js dependency
closes #1391

uglify-js is an optional dependency and should be treated as such.
This commit gracefully handles MODULE_NOT_FOUND errors while loading
uglify.

- Check for existing uglify-js (and load uglify-js) only if minification
  was activated
- Use "require.resolve" to check if uglify exists. Otherwise, a missing
  dependency of uglify-js would cause the same behavior as missing
  uglify-js. (Only a warning, no error)
- The code to load and run uglify is put into a single for readability
  purposes
- Tests use a mockup Module._resolveFilename to simulate the missing module.
  This function is used by both "require" and "require.resolve", so both
  are mocked equally.

(cherry picked from commit d5caa56)
2017-10-17 22:18:56 +02:00
Nils Knappmeier 5b76f041b3 Fix build on Windows
Closes #1233

- Handle path-separators properly. Use "path.sep" instead of "/".
  Or use "require.resolve()" if possible
- Use "execFile" instead of "exec" to run the Handlebars executable.
  This prevents problems due to (missing) shell escaping.
- Use explicit call to "node" in order to run the executable on Windows.
- Add "appveyor"-CI in order to run regular tests on Windows.
2017-08-23 22:29:30 +02:00