Skip to content

chore(deps-dev): bump handlebars from 4.7.9 to 4.7.10 - #3223

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/handlebars-4.7.10
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/handlebars-4.7.10

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Bumps handlebars from 4.7.9 to 4.7.10.

Release notes

Sourced from handlebars's releases.

v4.7.10

  • security: Sanitize the source map URL when minifying - f37c599
  • security: Iterate lazily in #each and strip whitespace in linear time - 812c226
  • security: Escape <!-- and <script in precompiled output - 609d1b1 GHSA-xw65-4hp5-5hc7
  • security: Don't trust special properties on context data - ceec388 GHSA-p8wg-vrv2-v86f
  • security: Only compile partials that are template strings - c28ee7a
  • security: Only dispatch known node types in the Compiler and Visitor - 7d501a5
  • security: Validate AST values in the compiler instead of the parser - 703fdcc GHSA-8r5x-fm3f-whwj
  • Clarify that --root does not restrict filesystem access - 0fcf25c
  • Bump minimist to ^1.2.8 - ea8ed82
  • Fix Ruby component publishing documentation - d069c1c
  • Fix Composer component definition - 6714e07

Compatibility notes:

  • {{#each}} iterates iterables such as Map, Set and generators lazily, like for...of, instead of copying them into an array first. Values added to the iterable while the block renders are now visited too.

Commits

Changelog

Sourced from handlebars's changelog.

v4.7.10 - October 5th, 2026

  • security: Sanitize the source map URL when minifying - f37c599
  • security: Iterate lazily in #each and strip whitespace in linear time - 812c226
  • security: Escape <!-- and <script in precompiled output - 609d1b1 GHSA-xw65-4hp5-5hc7
  • security: Don't trust special properties on context data - ceec388 GHSA-p8wg-vrv2-v86f
  • security: Only compile partials that are template strings - c28ee7a
  • security: Only dispatch known node types in the Compiler and Visitor - 7d501a5
  • security: Validate AST values in the compiler instead of the parser - 703fdcc GHSA-8r5x-fm3f-whwj
  • Clarify that --root does not restrict filesystem access - 0fcf25c
  • Bump minimist to ^1.2.8 - ea8ed82
  • Fix Ruby component publishing documentation - d069c1c
  • Fix Composer component definition - 6714e07

Compatibility notes:

  • {{#each}} iterates iterables such as Map, Set and generators lazily, like for...of, instead of copying them into an array first. Values added to the iterable while the block renders are now visited too.

Commits

Commits
  • 45ce152 v4.7.10
  • e47b236 Update release notes
  • f37c599 Sanitize the source map URL when minifying
  • 812c226 Iterate lazily in #each and strip whitespace in linear time
  • 609d1b1 Escape <!-- and <script in precompiled output
  • ceec388 Don't trust special properties on context data
  • c28ee7a Only compile partials that are template strings
  • 7d501a5 Only dispatch known node types in the Compiler and Visitor
  • 703fdcc Validate AST values in the compiler instead of the parser
  • 0fcf25c Clarify that --root does not restrict filesystem access
  • Additional commits viewable in compare view


Note

Low Risk
Patch-level dev dependency upgrade with security fixes; runtime CLI behavior is unchanged except for custom handlebars templates in build-docs.

Overview
Bumps the CLI’s devDependency handlebars from 4.7.9 to 4.7.10 in packages/cli/package.json, with matching lockfile updates (including minimist 1.2.6 → 1.2.8 via handlebars).

This picks up 4.7.10 security hardening (compiler/visitor validation, precompiled output escaping, context property handling, partial compilation restrictions, source map URL sanitization). Compatibility: {{#each}} now iterates Map/Set/generators lazily like for...of, which could affect custom doc templates that rely on the old snapshot behavior—build-docs uses handlebars for HTML templates in utils.ts.

Reviewed by Cursor Bugbot for commit c4f1be3. Bugbot is set up for automated code reviews on this repo. Configure here.

@dependabot
dependabot Bot requested a review from a team as a code owner October 9, 2026 07:26
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 9, 2026
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

📝 Recheck Summary

ℹ️ No Markdown files changed under docs/ or cookbook/.

@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Coverage Report

Status Category Percentage Covered / Total
🔵 Lines 83.16% (🎯 80%) 20421 / 24556
🔵 Statements 82.73% (🎯 80%) 22055 / 26658
🔵 Functions 84.39% (🎯 80%) 3846 / 4557
🔵 Branches 75.25% (🎯 75%) 14861 / 19748
File CoverageNo changed files found.
Generated in workflow #12479 for commit c4f1be3 by the Vitest Coverage Report Action

@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Performance Benchmark (Lower is Faster)

CLI Version Bundle Lint Check Config
latest ▓░░░░░░░░░░ 1.00x ▓░░░░░░░░░░ 1.00x ▓░░░░░░░░░░ 1.00x ± 0.02
next ▓░░░░░░░░░░ 1.02x ± 0.01 ▓░░░░░░░░░░ 1.00x ± 0.01 ▓░░░░░░░░░░ 1.00x

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/handlebars-4.7.10 branch from 6ee2ec0 to 075fbe4 Compare October 9, 2026 09:21
@changeset-bot

changeset-bot Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: c4f1be3

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

Bumps [handlebars](https://github.com/handlebars-lang/handlebars.js) from 4.7.9 to 4.7.10.
- [Release notes](https://github.com/handlebars-lang/handlebars.js/releases)
- [Changelog](https://github.com/handlebars-lang/handlebars.js/blob/v4.7.10/release-notes.md)
- [Commits](handlebars-lang/handlebars.js@v4.7.9...v4.7.10)

---
updated-dependencies:
- dependency-name: handlebars
  dependency-version: 4.7.10
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/handlebars-4.7.10 branch from 075fbe4 to c4f1be3 Compare October 9, 2026 12:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants