Comparing version 2.1.1 to 2.1.2
@@ -34,3 +34,3 @@ 'use strict'; | ||
var REGEXP_IGNORE_KEYS = /__proto__/; | ||
var REGEXP_IGNORE_KEYS = /__proto__|constructor|prototype/; | ||
@@ -37,0 +37,0 @@ var Parser = function () { |
{ | ||
"name": "multi-ini", | ||
"version": "2.1.1", | ||
"version": "2.1.2", | ||
"license": "MIT", | ||
@@ -5,0 +5,0 @@ "description": "An ini-file parser which supports multi line, multiple levels and arrays to get a maximum of compatibility with Zend config files.", |
@@ -140,2 +140,8 @@ # multi-ini [data:image/s3,"s3://crabby-images/fc0fc/fc0fcbfaaf85b7cc3b8df9a671e05c80ff5d86ef" alt="Build Status"](https://travis-ci.org/evangelion1204/multi-ini) [data:image/s3,"s3://crabby-images/ec6b4/ec6b420bdb37daeda9a800c6d8b33e41307993fd" alt="Coverage Status"](https://coveralls.io/r/evangelion1204/multi-ini?branch=master) | ||
### 2.1.2 | ||
* Fixed prototype pollution by ignoring `constructor` and `prototype` | ||
### 2.1.1 | ||
* Fixed prototype pollution by ignoring `__proto__` | ||
### 1.0.1 | ||
@@ -142,0 +148,0 @@ * Fixed bug with `keep_quotes` ignored when writing files |
@@ -23,3 +23,3 @@ 'use strict'; | ||
const REGEXP_IGNORE_KEYS = /__proto__/; | ||
const REGEXP_IGNORE_KEYS = /__proto__|constructor|prototype/; | ||
@@ -26,0 +26,0 @@ class Parser { |
Sorry, the diff of this file is not supported yet
85116
177