Skip to content

Conversation

@DavidTPate
Copy link
Contributor

This PR adds the license to the package file and updates web-resource-inliner so it uses the latest version which doesn't use the vulnerable version of uglify-js. The new version of web-resource-inliner has a PR already created jrit/web-resource-inliner#8 and this is being done in response to this advisory: https://nodesecurity.io/advisories/uglifyjs_incorrectly_handles_non-boolean_comparisons

…test version which doesn't use the vulnerable version of `uglify-js`.
@DavidTPate
Copy link
Contributor Author

The build should fail, as the new version of web-resource-inliner hasn't been released yet.

@jrit
Copy link
Collaborator

jrit commented Aug 25, 2015

Thanks again

jrit added a commit that referenced this pull request Aug 25, 2015
Update web-resource-inliner to the latest version, add license to package file
@jrit jrit merged commit 1560d42 into Automattic:master Aug 25, 2015
@DavidTPate DavidTPate deleted the update-web-resource-inliner branch August 25, 2015 18:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants