Skip to content

fix(deps): vuln patch upgrades — 5 packages (patch: 5) [node_modules/@octokit] - #44

Closed
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
masterfrom
engraver-auto-version-upgrade/minorpatch/npm/@octokit/0-1775089435
Closed

gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
masterfrom
engraver-auto-version-upgrade/minorpatch/npm/@octokit/0-1775089435

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown

Summary: Critical-severity security update — 15 packages upgraded (patch changes only)

Manifests changed:

  • node_modules/@octokit (npm)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

Package From To Type Vulnerabilities Fixed
handlebars 4.7.6 4.7.9 patch 5 CRITICAL, 4 HIGH, 2 MODERATE, 1 LOW
@types/fetch-mock 7.3.1 7.3.8 patch -
@types/fetch-mock 7.3.1 7.3.8 patch -
@types/fetch-mock 7.3.1 7.3.8 patch -
@types/fetch-mock 7.2.4 7.2.5 patch -
@types/fetch-mock 7.3.1 7.3.8 patch -
@types/jest 27.0.0 27.0.3 patch -
@types/jest 27.0.0 27.0.3 patch -
@types/jest 27.0.0 27.0.3 patch -
@types/jest 26.0.0 26.0.24 patch -
@types/jest 26.0.0 26.0.24 patch -
@types/jest 27.0.0 27.0.3 patch -
@types/jest 27.0.0 27.0.3 patch -
@types/node-fetch 2.3.3 2.3.7 patch -
fs-extra 10.0.0 10.0.1 patch -

Packages marked with "-" are updated due to dependency constraints.


Security Details

🚨 Critical & High Severity (9 fixed)
Package CVE Severity Summary Unsafe Version Fixed In
handlebars GHSA-2w6w-674q-4c4q CRITICAL Handlebars.js has JavaScript Injection via AST Type Confusion 4.7.6 4.7.9
handlebars GHSA-765h-qjxv-5f44 CRITICAL Prototype Pollution in handlebars 4.7.6 4.7.7
handlebars CVE-2021-23383 CRITICAL - 4.7.6 -
handlebars GHSA-f2jv-r9rf-7988 CRITICAL Remote code execution in handlebars when compiling templates 4.7.6 4.7.7
handlebars CVE-2021-23369 CRITICAL - 4.7.6 -
handlebars GHSA-9cx6-37pm-9jff HIGH Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation 4.7.6 4.7.9
handlebars GHSA-xhpv-hc6g-r9c6 HIGH Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial 4.7.6 4.7.9
handlebars GHSA-3mfm-83xf-c92r HIGH Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block 4.7.6 4.7.9
handlebars GHSA-xjpj-3mr7-gcpf HIGH Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options 4.7.6 4.7.9
ℹ️ Other Vulnerabilities (3)
Package CVE Severity Summary Unsafe Version Fixed In
handlebars GHSA-7rx3-28cr-v5wh MODERATE Handlebars.js has a Prototype Method Access Control Gap via Missing lookupSetter Blocklist Entry 4.7.6 4.7.9
handlebars GHSA-2qvq-rjwj-gvw9 MODERATE Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection 4.7.6 4.7.9
handlebars GHSA-442j-39wm-28r2 LOW Handlebars.js has a Property Access Validation Bypass in container.lookup 4.7.6 4.7.9

Review Checklist

Standard review:

  • Review changes for compatibility with your code
  • Check for breaking changes in release notes
  • Run tests locally or wait for CI
  • Approve and merge this PR

Update Mode: Vulnerability Remediation (Critical/High)

🤖 Generated by DataDog Automated Dependency Management System

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants