Commit ef7eb5d
[fix]: bump handlebars to 4.7.9 (SECURE-3011)
CVE-2026-33941 / GHSA-xjpj-3mr7-gcpf — handlebars CLI precompiler
code injection / XSS vulnerability. handlebars is a transitive
devDependency via plop → node-plop, so production bundles are not
affected, but we bump for supply-chain hygiene.
Forced via yarn resolutions since node-plop pins ^4.4.3.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>1 parent 5f0125c commit ef7eb5d
2 files changed
Lines changed: 6 additions & 5 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
170 | 170 | | |
171 | 171 | | |
172 | 172 | | |
173 | | - | |
| 173 | + | |
| 174 | + | |
174 | 175 | | |
175 | 176 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
8183 | 8183 | | |
8184 | 8184 | | |
8185 | 8185 | | |
8186 | | - | |
8187 | | - | |
8188 | | - | |
| 8186 | + | |
| 8187 | + | |
| 8188 | + | |
8189 | 8189 | | |
8190 | 8190 | | |
8191 | 8191 | | |
| |||
8197 | 8197 | | |
8198 | 8198 | | |
8199 | 8199 | | |
8200 | | - | |
| 8200 | + | |
8201 | 8201 | | |
8202 | 8202 | | |
8203 | 8203 | | |
| |||
0 commit comments