Skip to content

chore(deps): override vulnerable handlebars - #7699

Merged
viceice merged 1 commit into
mainfrom
viceice/fix/handlebars-override
Oct 9, 2026
Merged

viceice merged 1 commit into
mainfrom
viceice/fix/handlebars-override

Conversation

@viceice

@viceice viceice commented Oct 9, 2026

Copy link
Copy Markdown
Member

Changes

Override from pnpm audit --fix: handlebars → 4.7.10 (dev only, via semantic-release's conventional-changelog-writer).

braces and sprintf-js still have no fixed release and stay as they are.

Context

Please select one of the following:

  • This closes an existing Issue, Closes: #
  • This doesn't close an Issue, but I accept the risk that this PR may be closed if maintainers disagree with its opening or implementation

AI assistance disclosure

Did you use AI tools to create any part of this pull request?

Please select one option and, if yes, briefly describe how AI was used (e.g., code, tests, docs) and which tool(s) you used.

  • No — I did not use AI for this contribution.
  • Yes — minimal assistance (e.g., IDE autocomplete, small code completions, grammar fixes).
  • Yes — substantive assistance (AI-generated non‑trivial portions of code, tests, or documentation).
  • Yes — other (please describe):

Written by Claude Opus 5.5 in Claude Code.

Use of AI in replying to PR comments

Who answers review comments:

  • @viceice will read and reply directly. Name the account.
  • An agent will draft replies and @username will read them before they are posted. Name the account.
  • An agent will draft replies and reply autonomously. This is heavily discouraged, and we prefer that there are humans in the loop
  • Nobody has explicitly committed to replying.

Documentation (please check one with an [x])

  • I have updated the documentation, or
  • No documentation update is required

How I've tested my work (please select one)

I have verified these changes via:

  • Code inspection only, or
  • Newly added/modified tests

pnpm audit only reports braces and sprintf-js afterwards.

🤖 Generated with Claude Code

Co-Authored-By: Claude Opus 5.5 <michael.kriese+claude-code@mend.io>
@viceice
viceice enabled auto-merge October 9, 2026 10:03
@coderabbitai

coderabbitai Bot commented Oct 9, 2026

Copy link
Copy Markdown

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 9 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Repository: containerbase/coderabbit/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: d3ed25c8-0217-463c-8adb-d1f960ba325f

📥 Commits

Reviewing files that changed from the base of the PR and between 2533378 and a893558.


⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml

📒 Files selected for processing (1)
  • pnpm-workspace.yaml


  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@qodo-code-review

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Grey Divider

Great, no issues found!

Qodo reviewed your code and found no material issues that require review

Grey Divider

Tip of the day
💡 Did you know, you can show, collapse, or hide each part of a finding: code, evidence, and all

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

@qodo-code-review

Copy link
Copy Markdown

PR Summary by Qodo

Override vulnerable transitive Handlebars with 4.7.10

⚙️ Configuration changes 🕐 Less than 10 minutes

Grey Divider

AI Description

• Override vulnerable Handlebars versions with 4.7.10 in the development dependency tree.
• Refresh the lockfile so conventional-changelog-writer resolves the patched version.
Diagram

graph TD
  A["Semantic release"] --> B["Changelog writer"] --> C["Handlebars 4.7.10"]
  D["Workspace override"] --> E["pnpm lockfile"] --> C
Loading
High-Level Assessment

Keep the targeted pnpm override: Handlebars is transitive, so changing a direct dependency would be broader than necessary. The matching lockfile update records the patched resolution.

Files changed (2) +6 / -4

Other (2) +6 / -4
pnpm-workspace.yamlOverride vulnerable Handlebars versions +1/-0

Override vulnerable Handlebars versions

• Adds an override that resolves Handlebars versions from 4.0.0 through 4.7.9 to 4.7.10.

pnpm-workspace.yaml

pnpm-lock.yamlLock the patched transitive Handlebars version +5/-4

Lock the patched transitive Handlebars version

• Records the override and replaces Handlebars 4.7.9 with 4.7.10 in the package resolution and conventional-changelog-writer dependency snapshot.

pnpm-lock.yaml

@viceice
viceice added this pull request to the merge queue Oct 9, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 9, 2026
@viceice
viceice added this pull request to the merge queue Oct 9, 2026
Merged via the queue into main with commit 89b1df1 Oct 9, 2026
61 checks passed
@viceice
viceice deleted the viceice/fix/handlebars-override branch October 9, 2026 12:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant