Skip to content

MAINT: Bump handlebars from 4.7.9 to 4.7.10 in /frontend in the security-minor-and-patch group across 1 directory - #3054

Merged
Roman Lutz (romanlutz) merged 2 commits into
mainfrom
dependabot/npm_and_yarn/frontend/security-minor-and-patch-c6d5a854cf
Oct 10, 2026
Merged

Roman Lutz (romanlutz) merged 2 commits into
mainfrom
dependabot/npm_and_yarn/frontend/security-minor-and-patch-c6d5a854cf

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor

Bumps the security-minor-and-patch group with 1 update in the /frontend directory: handlebars.

Updates handlebars from 4.7.9 to 4.7.10

Release notes

Sourced from handlebars's releases.

v4.7.10

  • security: Sanitize the source map URL when minifying - f37c599
  • security: Iterate lazily in #each and strip whitespace in linear time - 812c226
  • security: Escape <!-- and <script in precompiled output - 609d1b1 GHSA-xw65-4hp5-5hc7
  • security: Don't trust special properties on context data - ceec388 GHSA-p8wg-vrv2-v86f
  • security: Only compile partials that are template strings - c28ee7a
  • security: Only dispatch known node types in the Compiler and Visitor - 7d501a5
  • security: Validate AST values in the compiler instead of the parser - 703fdcc GHSA-8r5x-fm3f-whwj
  • Clarify that --root does not restrict filesystem access - 0fcf25c
  • Bump minimist to ^1.2.8 - ea8ed82
  • Fix Ruby component publishing documentation - d069c1c
  • Fix Composer component definition - 6714e07

Compatibility notes:

  • {{#each}} iterates iterables such as Map, Set and generators lazily, like for...of, instead of copying them into an array first. Values added to the iterable while the block renders are now visited too.

Commits

Changelog

Sourced from handlebars's changelog.

v4.7.10 - October 5th, 2026

  • security: Sanitize the source map URL when minifying - f37c599
  • security: Iterate lazily in #each and strip whitespace in linear time - 812c226
  • security: Escape <!-- and <script in precompiled output - 609d1b1 GHSA-xw65-4hp5-5hc7
  • security: Don't trust special properties on context data - ceec388 GHSA-p8wg-vrv2-v86f
  • security: Only compile partials that are template strings - c28ee7a
  • security: Only dispatch known node types in the Compiler and Visitor - 7d501a5
  • security: Validate AST values in the compiler instead of the parser - 703fdcc GHSA-8r5x-fm3f-whwj
  • Clarify that --root does not restrict filesystem access - 0fcf25c
  • Bump minimist to ^1.2.8 - ea8ed82
  • Fix Ruby component publishing documentation - d069c1c
  • Fix Composer component definition - 6714e07

Compatibility notes:

  • {{#each}} iterates iterables such as Map, Set and generators lazily, like for...of, instead of copying them into an array first. Values added to the iterable while the block renders are now visited too.

Commits

Commits
  • 45ce152 v4.7.10
  • e47b236 Update release notes
  • f37c599 Sanitize the source map URL when minifying
  • 812c226 Iterate lazily in #each and strip whitespace in linear time
  • 609d1b1 Escape <!-- and <script in precompiled output
  • ceec388 Don't trust special properties on context data
  • c28ee7a Only compile partials that are template strings
  • 7d501a5 Only dispatch known node types in the Compiler and Visitor
  • 703fdcc Validate AST values in the compiler instead of the parser
  • 0fcf25c Clarify that --root does not restrict filesystem access
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps the security-minor-and-patch group with 1 update in the /frontend directory: [handlebars](https://github.com/handlebars-lang/handlebars.js).


Updates `handlebars` from 4.7.9 to 4.7.10
- [Release notes](https://github.com/handlebars-lang/handlebars.js/releases)
- [Changelog](https://github.com/handlebars-lang/handlebars.js/blob/v4.7.10/release-notes.md)
- [Commits](handlebars-lang/handlebars.js@v4.7.9...v4.7.10)

---
updated-dependencies:
- dependency-name: handlebars
  dependency-version: 4.7.10
  dependency-type: indirect
  dependency-group: security-minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 9, 2026
@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Pytest (3.13, dev)

     1 files  ±0       1 suites  ±0   4m 41s ⏱️ -42s
24 768 tests ±0  24 451 ✅ ±0  317 💤 ±0  0 ❌ ±0 
24 849 runs  ±0  24 532 ✅ ±0  317 💤 ±0  0 ❌ ±0 

Results for commit 4166e19. ± Comparison against base commit 4beda9c.

♻️ This comment has been updated with latest results.

@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Pytest (3.13, dev_all)

     1 files  ±0       1 suites  ±0   5m 41s ⏱️ + 1m 48s
25 098 tests ±0  25 092 ✅ ±0  6 💤 ±0  0 ❌ ±0 
25 179 runs  ±0  25 173 ✅ ±0  6 💤 ±0  0 ❌ ±0 

Results for commit 4166e19. ± Comparison against base commit 4beda9c.

♻️ This comment has been updated with latest results.

@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Pytest (3.14, dev)

     1 files  ±0       1 suites  ±0   4m 15s ⏱️ -14s
24 768 tests ±0  24 451 ✅ ±0  317 💤 ±0  0 ❌ ±0 
24 849 runs  ±0  24 532 ✅ ±0  317 💤 ±0  0 ❌ ±0 

Results for commit 4166e19. ± Comparison against base commit 4beda9c.

♻️ This comment has been updated with latest results.

@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Pytest (3.12, dev)

     1 files  ±0       1 suites  ±0   4m 16s ⏱️ +27s
24 768 tests ±0  24 451 ✅ ±0  317 💤 ±0  0 ❌ ±0 
24 849 runs  ±0  24 532 ✅ ±0  317 💤 ±0  0 ❌ ±0 

Results for commit 4166e19. ± Comparison against base commit 4beda9c.

♻️ This comment has been updated with latest results.

@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Pytest (3.11, dev_all)

     1 files  ±0       1 suites  ±0   4m 34s ⏱️ +44s
25 098 tests ±0  25 092 ✅ ±0  6 💤 ±0  0 ❌ ±0 
25 179 runs  ±0  25 173 ✅ ±0  6 💤 ±0  0 ❌ ±0 

Results for commit 4166e19. ± Comparison against base commit 4beda9c.

♻️ This comment has been updated with latest results.

@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Pytest (3.12, dev_all)

     1 files  ±0       1 suites  ±0   4m 0s ⏱️ - 2m 37s
25 098 tests ±0  25 092 ✅ ±0  6 💤 ±0  0 ❌ ±0 
25 179 runs  ±0  25 173 ✅ ±0  6 💤 ±0  0 ❌ ±0 

Results for commit 4166e19. ± Comparison against base commit 4beda9c.

♻️ This comment has been updated with latest results.

@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Pytest (3.14, dev_all)

     1 files  ±0       1 suites  ±0   4m 38s ⏱️ +18s
25 098 tests ±0  25 092 ✅ ±0  6 💤 ±0  0 ❌ ±0 
25 179 runs  ±0  25 173 ✅ ±0  6 💤 ±0  0 ❌ ±0 

Results for commit 4166e19. ± Comparison against base commit 4beda9c.

♻️ This comment has been updated with latest results.

@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Pytest (3.11, dev)

     1 files  ±0       1 suites  ±0   4m 7s ⏱️ +11s
24 768 tests ±0  24 451 ✅ ±0  317 💤 ±0  0 ❌ ±0 
24 849 runs  ±0  24 532 ✅ ±0  317 💤 ±0  0 ❌ ±0 

Results for commit 4166e19. ± Comparison against base commit 4beda9c.

♻️ This comment has been updated with latest results.

@spencrr
Spencer Schoenberg (spencrr) added this pull request to the merge queue Oct 9, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to no response for status checks Oct 9, 2026
@romanlutz
Roman Lutz (romanlutz) added this pull request to the merge queue Oct 10, 2026
Merged via the queue into main with commit f1731cc Oct 10, 2026
61 checks passed
@romanlutz
Roman Lutz (romanlutz) deleted the dependabot/npm_and_yarn/frontend/security-minor-and-patch-c6d5a854cf branch October 10, 2026 00:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants