SIGN IN SIGN UP

Fix critical vulnerabilities from daily dependency scan (#21402)

* Fix CVE-2026-33937: resolve handlebars to 4.7.9

grpc_tools_node_protoc_ts pins handlebars 4.7.7 and has no fixed
release. Use yarn resolutions to force 4.7.9 which patches the
JavaScript injection via AST type confusion vulnerability.

Co-authored-by: Ona <no-reply@ona.com>

* Fix protobufjs arbitrary code execution: bump to 7.5.5

Lockfile-only change. Both @grpc/proto-loader (^7.2.5) and ts-proto
(^7.2.4) already accept 7.5.5 via semver, so no package.json or
resolution changes needed.

Co-authored-by: Ona <no-reply@ona.com>

---------

Co-authored-by: Ona <no-reply@ona.com>
G
Gero Posmyk-Leinemann committed
3d124ef857ee2d8ae44e4b8e1e7687ab5da0870d
Parent: 0900b8d
Committed by GitHub <noreply@github.com> on 4/17/2026, 7:42:56 AM