Skip to content

Commit 73bb214

Browse files
sbouchetclaude
authored andcommitted
Fix handlebars vulnerabilities by overriding to 4.7.9
Override handlebars to 4.7.9 in che-api, che-port, che-remote, che-resource-monitor, and launcher to fix 8 vulnerabilities including critical JS injection (CVSS 9.8) and multiple high severity issues affecting versions 4.0.0-4.7.8. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
1 parent ace935b commit 73bb214

10 files changed

Lines changed: 25 additions & 20 deletions

File tree

code/extensions/che-api/package-lock.json

Lines changed: 3 additions & 3 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

code/extensions/che-api/package.json

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -51,7 +51,8 @@
5151
"webpack-node-externals": "^3.0.0"
5252
},
5353
"overrides": {
54-
"minimatch": "^3.1.5"
54+
"minimatch": "^3.1.5",
55+
"handlebars": "4.7.9"
5556
},
5657
"repository": {
5758
"type": "git",

code/extensions/che-port/package-lock.json

Lines changed: 3 additions & 3 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

code/extensions/che-port/package.json

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -54,7 +54,8 @@
5454
"jsdom": {
5555
"form-data": "3.0.4"
5656
},
57-
"minimatch": "^3.1.5"
57+
"minimatch": "^3.1.5",
58+
"handlebars": "4.7.9"
5859
},
5960
"repository": {
6061
"type": "git",

code/extensions/che-remote/package-lock.json

Lines changed: 3 additions & 3 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

code/extensions/che-remote/package.json

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -59,7 +59,8 @@
5959
},
6060
"lodash": "^4.17.23",
6161
"ajv": "6.14.0",
62-
"minimatch": "^3.1.5"
62+
"minimatch": "^3.1.5",
63+
"handlebars": "4.7.9"
6364
},
6465
"repository": {
6566
"type": "git",

code/extensions/che-resource-monitor/package-lock.json

Lines changed: 3 additions & 3 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

code/extensions/che-resource-monitor/package.json

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -47,7 +47,8 @@
4747
"ts-jest": "29.4.5"
4848
},
4949
"overrides": {
50-
"minimatch": "^3.1.5"
50+
"minimatch": "^3.1.5",
51+
"handlebars": "4.7.9"
5152
},
5253
"repository": {
5354
"type": "git",

launcher/package-lock.json

Lines changed: 3 additions & 3 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

launcher/package.json

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -52,7 +52,8 @@
5252
"ajv": "^8.18.0"
5353
},
5454
"ajv": "6.14.0",
55-
"minimatch": "^3.1.5"
55+
"minimatch": "^3.1.5",
56+
"handlebars": "4.7.9"
5657
},
5758
"jest": {
5859
"collectCoverage": true,

0 commit comments

Comments
 (0)