From fb723965a9b89cfe8e289665f749d699ae81729d Mon Sep 17 00:00:00 2001 From: Galina Yermicheva Date: Thu, 16 Apr 2026 16:39:36 -0400 Subject: [PATCH] =?UTF-8?q?fix(deps):=20bump=20handlebars=204.7.8=20?= =?UTF-8?q?=E2=86=92=204.7.9=20(CVE-2026-33937)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Resolves CVE-2026-33937 (CVSS 9.8 Critical): JavaScript Injection via AST Type Confusion in Handlebars.js. handlebars was a transitive dependency via semantic-release → conventional-changelog-writer@7.0.1, which already specifies ^4.7.7. Updated pnpm-lock.yaml to resolve to 4.7.9. --- pnpm-lock.yaml | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index 757e75c..b1d5625 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -2270,8 +2270,8 @@ packages: graphemer@1.4.0: resolution: {integrity: sha512-EtKwoO6kxCL9WO5xipiHTZlSzBm7WLT627TqC/uVRd0HKmq8NXyebnNYxDoBi7wt8eTWrUrKXCOVaFq9x1kgag==} - handlebars@4.7.8: - resolution: {integrity: sha512-vafaFqs8MZkRrSX7sFVUdo3ap/eNiLnb4IakshzvP56X5Nr1iGKAIqdX6tMlm6HcNRIkr6AxO5jFEoJzzpT8aQ==} + handlebars@4.7.9: + resolution: {integrity: sha512-4E71E0rpOaQuJR2A3xDZ+GM1HyWYv1clR58tC8emQNeQe3RH7MAzSbat+V0wG78LQBo6m6bzSG/L4pBuCsgnUQ==} engines: {node: '>=0.4.7'} hasBin: true @@ -6228,7 +6228,7 @@ snapshots: conventional-changelog-writer@7.0.1: dependencies: conventional-commits-filter: 4.0.0 - handlebars: 4.7.8 + handlebars: 4.7.9 json-stringify-safe: 5.0.1 meow: 12.1.1 semver: 7.7.3 @@ -6976,7 +6976,7 @@ snapshots: graphemer@1.4.0: {} - handlebars@4.7.8: + handlebars@4.7.9: dependencies: minimist: 1.2.8 neo-async: 2.6.2