From 981a451d82f11a93966c51d829e2bf4fd8a0a8ad Mon Sep 17 00:00:00 2001 From: greenkeeperio-bot Date: Fri, 29 Apr 2016 11:27:51 -0700 Subject: [PATCH 1/2] chore(package): update helmet to version 2.0.0 https://greenkeeper.io/ --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index 4ac012c6c1..54f64cef12 100644 --- a/package.json +++ b/package.json @@ -72,7 +72,7 @@ "gulp-rev-replace": "~0.4.2", "gulp-uglify": "^1.5.1", "gulp-util": "^3.0.6", - "helmet": "^1.1.0", + "helmet": "^2.0.0", "helmet-csp": "^1.0.3", "history": "^2.0.0", "jade": "^1.11.0", From 1ea2c2a20ad3d7708a39ccdff5bb10ec21e55aef Mon Sep 17 00:00:00 2001 From: Logan Tegman Date: Tue, 3 May 2016 11:32:28 -0700 Subject: [PATCH 2/2] helmet.csp -> helmet.contentSecurityPolicy Also updated frameguard --- package.json | 2 +- server/middlewares/csp.js | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/package.json b/package.json index 54f64cef12..39b2af7a62 100644 --- a/package.json +++ b/package.json @@ -57,7 +57,7 @@ "express-state": "^1.2.0", "express-validator": "^2.18.0", "fetchr": "~0.5.12", - "frameguard": "~1.1.0", + "frameguard": "^2.0.0", "gulp": "^3.9.0", "gulp-babel": "^6.1.1", "gulp-concat": "^2.6.0", diff --git a/server/middlewares/csp.js b/server/middlewares/csp.js index b64036275b..599964bc45 100644 --- a/server/middlewares/csp.js +++ b/server/middlewares/csp.js @@ -9,7 +9,7 @@ if (process.env.NODE_ENV !== 'production') { } export default function csp() { - return helmet.csp({ + return helmet.contentSecurityPolicy({ directives: { defaultSrc: trusted, scriptSrc: [