Repository navigation
fix(deps): update handlebars to 4.7.10 to clear three critical advisories - #1307
Merged
Merged
Conversation
…ries The self-scan raised three critical alerts on handlebars@4.7.9 after #1305 bumped ts-jest: GHSA-8r5x-fm3f-whwj, GHSA-p8wg-vrv2-v86f and GHSA-xw65-4hp5-5hc7, all fixed in 4.7.10. No version bump needed anywhere. ts-jest declares handlebars ^4.7.9, which already permits 4.7.10, so this is the within-range case our own output described as "ts-jest already permits handlebars@4.7.10". Only the lockfile moves. Our own scan now reports zero critical and zero high, with one medium left: sprintf-js@1.0.3, transitive through jest and genuinely unfixable, since 1.1.3 is the newest published version and carries the same advisory. Closes #1306
|
1 critical finding resolved by this PR
Only findings this PR changed are listed. Nothing is posted when the set is unchanged. Scanned by CVE Lite CLI, a free and open source OWASP project. ❤️ ShareIf this caught something before it merged, a mention helps other maintainers find it.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Three critical advisories against
handlebars@4.7.9, all fixed in4.7.10:GHSA-8r5x-fm3f-whwj,GHSA-p8wg-vrv2-v86fandGHSA-xw65-4hp5-5hc7. They were open on our own Security tab.No version bump anywhere.
ts-jestdeclareshandlebars: ^4.7.9, which already permits4.7.10, so only the lockfile moves. This is the within-range case our own output describes asts-jest already permits handlebars@4.7.10.They arrived with #1305, a Self Fix PR that cleared one medium
ts-jestadvisory and brought in three criticals with the newer version. Nothing flagged that trade at merge time, because a Self Fix PR is not scanned against its own result; the next scheduled self-scan found it.Our own scan now reports zero critical and zero high. The one medium left is
sprintf-js@1.0.3, transitive through jest and genuinely unfixable, since1.1.3is the newest published version and carries the same advisory.Closes #1306