Repository navigation
fix(deps): CVE-2026-106446 (critical) + CVE-2026-106445 (critical) — bump handlebars to 4.7.10 - #1964
Conversation
…critical) Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
|
I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".
|
🦋 Changeset detectedLatest commit: d520c0a The changes in this PR will be included in the next version bump. This PR includes changesets to release 1 package
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Package ArtifactsBuilt from 4e3b701. Download artifacts from this workflow run. JS SDK ( npm install ./e2b-dockerfile-utils-0.1.1-devin-1791529556-handlebars-cve.0.tgz ./e2b-2.54.1-devin-1791529556-handlebars-cve.0.tgzCLI ( npm install ./e2b-cli-2.21.2-devin-1791529556-handlebars-cve.0.tgzCode Interpreter JS SDK ( npm install ./e2b-code-interpreter-2.8.3-devin-1791529556-handlebars-cve.0.tgzDesktop JS SDK ( npm install ./e2b-desktop-2.4.1-devin-1791529556-handlebars-cve.0.tgzPython SDK ( pip install ./e2b_dockerfile_utils-0.1.0+devin.1791529556.handlebars.cve-py3-none-any.whl ./e2b-2.54.0+devin.1791529556.handlebars.cve-py3-none-any.whlCode Interpreter Python SDK ( pip install ./e2b_code_interpreter-2.10.3+devin.1791529556.handlebars.cve-py3-none-any.whlDesktop Python SDK ( pip install ./e2b_desktop-2.6.1+devin.1791529556.handlebars.cve-py3-none-any.whl |
|
CI note: the only failure is |
Summary
pnpm auditflagshandlebars@4.7.9, a direct runtime dependency of@e2b/cli. It's in published code:src/commands/template/generators/handlebars.tscallshandlebars.compile()to render the files thate2b template init/e2b template migrategenerate, and tsdown bundles it intodist/index.js.compile(bypass of CVE-2026-33937)This is a patch bump (smallest version that clears all three). The two critical CVEs are in one PR because the same one-line bump fixes both, and splitting them would just produce two identical, conflicting PRs. 4.7.10 was published 2026-10-05 22:37 UTC, so it's already past the workspace's
minimumReleaseAge(3 days). The lockfile diff only toucheshandlebars(also re-resolved under@types/handlebars). Includes a@e2b/clipatch changeset.Verified locally:
pnpm auditno longer reports handlebars.@e2b/clitypecheckandbuildpass, andvitest runpasses (19 files / 139 tests, including the templateinit/migratetests that render through Handlebars).Link to Devin session: https://app.devin.ai/sessions/b8295685b92640839d4f6176892cc5e7
Open in Devin Desktop: https://app.devin.ai/desktop/session/b8295685b92640839d4f6176892cc5e7?variant=devin