Skip to content

Fix critical Handlebars CVEs from daily vulnerability scan - #21635

Draft
kylos101 wants to merge 1 commit into
mainfrom
fix/critical-handlebars-cves
Draft

kylos101 wants to merge 1 commit into
mainfrom
fix/critical-handlebars-cves

Conversation

@kylos101

Copy link
Copy Markdown
Contributor

Summary

The latest scheduled main build reported four distinct CRITICAL npm advisories across the shared Yarn dependency graph. Open draft PRs #21633 and #21634 already address proxy-addr and shell-quote; this PR fixes the two newly reported Handlebars advisories without duplicating that work.

Package From To Advisories
handlebars 4.7.9 4.7.10 GHSA-8r5x-fm3f-whwj / CVE-2026-106446; GHSA-p8wg-vrv2-v86f / CVE-2026-106445

The affected artifacts include the dashboard, database, supervisor frontend, workspace manager bridge, server image, and generated TypeScript API packages. They inherit Handlebars from the root Yarn resolution and lockfile.

Validation

  • yarn install --pure-lockfile --ignore-scripts --force --non-interactive
  • Verified installed Handlebars version is 4.7.10
  • Grype scan of yarn.lock: zero matches for both targeted advisories and zero remaining Handlebars matches
  • pre-commit run --files package.json yarn.lock
  • git diff --check

Co-authored-by: Codex <noreply@openai.com>

This branch was successfully deployed

1 active deployment
branch-build — 4a9677f2 Deployed Oct 10, 2026 by kylos101 via Build Gitpod #383
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant