Skip to content

fix: update handlebars to resolve CVE-2026-33937#33

Open
dannyneira wants to merge 1 commit into
mainfrom
independabot/handlebars-cve-2026-33937
Open

fix: update handlebars to resolve CVE-2026-33937#33
dannyneira wants to merge 1 commit into
mainfrom
independabot/handlebars-cve-2026-33937

Conversation

@dannyneira
Copy link
Copy Markdown
Member

Summary

Vulnerability details

Verification

  • pnpm install --frozen-lockfile
  • pnpm why handlebars shows only handlebars@4.7.9
  • pnpm audit --json reports no handlebars advisories remaining
  • pnpm lint
  • pnpm build
  • pnpm test

Note: pnpm audit still reports unrelated advisories for ajv, brace-expansion, diff, flatted, minimatch, and picomatch; this PR only targets the selected grouped handlebars alerts.

Conversation: https://staging.warp.dev/conversation/864d183d-4feb-4516-abb6-71b7afef83f0
Run: https://oz.staging.warp.dev/runs/019e7ec3-80f0-7400-9dff-fd0cda5df33b
This PR was generated with Oz.

Co-Authored-By: Oz <oz-agent@warp.dev>
@dannyneira dannyneira requested a review from ianhodge May 31, 2026 16:05
@dannyneira dannyneira marked this pull request as ready for review June 1, 2026 20:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants