Skip to content

fix(deps): update handlebars to 4.7.10 to clear three critical advisories - #1307

Merged
sonukapoor merged 1 commit into
mainfrom
fix/handlebars-4-7-10
Oct 9, 2026
Merged

sonukapoor merged 1 commit into
mainfrom
fix/handlebars-4-7-10

Conversation

@sonukapoor

Copy link
Copy Markdown
Collaborator

Three critical advisories against handlebars@4.7.9, all fixed in 4.7.10: GHSA-8r5x-fm3f-whwj, GHSA-p8wg-vrv2-v86f and GHSA-xw65-4hp5-5hc7. They were open on our own Security tab.

No version bump anywhere. ts-jest declares handlebars: ^4.7.9, which already permits 4.7.10, so only the lockfile moves. This is the within-range case our own output describes as ts-jest already permits handlebars@4.7.10.

They arrived with #1305, a Self Fix PR that cleared one medium ts-jest advisory and brought in three criticals with the newer version. Nothing flagged that trade at merge time, because a Self Fix PR is not scanned against its own result; the next scheduled self-scan found it.

Our own scan now reports zero critical and zero high. The one medium left is sprintf-js@1.0.3, transitive through jest and genuinely unfixable, since 1.1.3 is the newest published version and carries the same advisory.

Closes #1306

…ries

The self-scan raised three critical alerts on handlebars@4.7.9 after #1305 bumped
ts-jest: GHSA-8r5x-fm3f-whwj, GHSA-p8wg-vrv2-v86f and GHSA-xw65-4hp5-5hc7, all
fixed in 4.7.10.

No version bump needed anywhere. ts-jest declares handlebars ^4.7.9, which
already permits 4.7.10, so this is the within-range case our own output described
as "ts-jest already permits handlebars@4.7.10". Only the lockfile moves.

Our own scan now reports zero critical and zero high, with one medium left:
sprintf-js@1.0.3, transitive through jest and genuinely unfixable, since 1.1.3 is
the newest published version and carries the same advisory.

Closes #1306
@cve-lite-cli-bot

Copy link
Copy Markdown

CVE Lite CLI

1 critical finding resolved by this PR

Only findings this PR changed are listed. Nothing is posted when the set is unchanged.

Scanned by CVE Lite CLI, a free and open source OWASP project.

❤️ Share

If this caught something before it merged, a mention helps other maintainers find it.

  • Post on X

  • Share on LinkedIn

  • Add the badge to your README:

    [![Protected by CVE Lite CLI](https://img.shields.io/badge/Protected_by-CVE_Lite_CLI-brightgreen)](https://github.com/OWASP/cve-lite-cli)

@sonukapoor
sonukapoor merged commit 1f8b73f into main Oct 9, 2026
6 checks passed
@sonukapoor
sonukapoor deleted the fix/handlebars-4-7-10 branch October 9, 2026 12:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(deps): handlebars@4.7.9 carries three critical advisories, arrived with the ts-jest bump

1 participant