Skip to content

Conversation

@sseide
Copy link

@sseide sseide commented Feb 10, 2021

backported fix for code injection (#571 and abaee2b) to the 2.x branch of ejs.

As this branch contains lot less dependencies it is the better choice for browser-side integration as long as there is no extra ejs-cli package. And all other dependencies of the 2.x branch are up to date (regarding security problems), therefor its safe to use.

Please merge this and publish a new version 2.7.5 to npm.

Many Thanks in advance,
Stefan Seide

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants