Skip to content

chore(deps-dev): bump handlebars from 4.7.8 to 4.7.9#1014

Merged
tsi merged 1 commit intodependabot/npm_and_yarn/multi-28b8dc3d4efrom
dependabot/npm_and_yarn/handlebars-4.7.9
Apr 26, 2026
Merged

chore(deps-dev): bump handlebars from 4.7.8 to 4.7.9#1014
tsi merged 1 commit intodependabot/npm_and_yarn/multi-28b8dc3d4efrom
dependabot/npm_and_yarn/handlebars-4.7.9

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Mar 26, 2026

Bumps handlebars from 4.7.8 to 4.7.9.

Release notes

Sourced from handlebars's releases.

v4.7.9

Commits

Changelog

Sourced from handlebars's changelog.

v4.7.9 - March 26th, 2026

  • fix: enable shell mode for spawn to resolve Windows EINVAL issue - e0137c2
  • fix type "RuntimeOptions" also accepting string partials - eab1d14
  • feat(types): set hash to be a Record<string, any> - de4414d
  • fix non-contiguous program indices - 4512766
  • refactor: rename i to startPartIndex - e497a35
  • security: fix security issues - 68d8df5

Commits

Commits
  • dce542c v4.7.9
  • 8a41389 Update release notes
  • 68d8df5 Fix security issues
  • b2a0831 Fix browser tests
  • 9f98c16 Fix release script
  • 45443b4 Revert "Improve partial indenting performance"
  • 8841a5f Fix CI errors with linting
  • e0137c2 fix: enable shell mode for spawn to resolve Windows EINVAL issue
  • e914d60 Improve rendering performance
  • 7de4b41 Upgrade GitHub Actions checkout and setup-node on 4.x branch
  • Additional commits viewable in compare view

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Mar 26, 2026
@dependabot dependabot Bot requested a review from a team as a code owner March 26, 2026 23:00
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Mar 26, 2026
@netlify
Copy link
Copy Markdown

netlify Bot commented Mar 26, 2026

Deploy Preview for cld-video-player ready!

Name Link
🔨 Latest commit e3e92cb
🔍 Latest deploy log https://app.netlify.com/projects/cld-video-player/deploys/69e5f87fab58220008500304
😎 Deploy Preview https://deploy-preview-1014--cld-video-player.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@netlify
Copy link
Copy Markdown

netlify Bot commented Mar 26, 2026

Deploy Preview for cld-vp-esm-pages ready!

Name Link
🔨 Latest commit e3e92cb
🔍 Latest deploy log https://app.netlify.com/projects/cld-vp-esm-pages/deploys/69e5f87fab58220008500306
😎 Deploy Preview https://deploy-preview-1014--cld-vp-esm-pages.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/handlebars-4.7.9 branch from 15db40c to 4df69f2 Compare April 2, 2026 13:47
Bumps [handlebars](https://github.com/handlebars-lang/handlebars.js) from 4.7.8 to 4.7.9.
- [Release notes](https://github.com/handlebars-lang/handlebars.js/releases)
- [Changelog](https://github.com/handlebars-lang/handlebars.js/blob/v4.7.9/release-notes.md)
- [Commits](handlebars-lang/handlebars.js@v4.7.8...v4.7.9)

---
updated-dependencies:
- dependency-name: handlebars
  dependency-version: 4.7.9
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/handlebars-4.7.9 branch from 4df69f2 to e3e92cb Compare April 20, 2026 09:57
@tsi tsi changed the base branch from master to dependabot/npm_and_yarn/multi-28b8dc3d4e April 26, 2026 09:20
@tsi tsi merged commit 5250539 into dependabot/npm_and_yarn/multi-28b8dc3d4e Apr 26, 2026
9 of 10 checks passed
@dependabot dependabot Bot deleted the dependabot/npm_and_yarn/handlebars-4.7.9 branch April 26, 2026 09:21
tsi added a commit that referenced this pull request Apr 26, 2026
* chore(deps): bump axios and bundlewatch

Bumps [axios](https://github.com/axios/axios) to 1.15.2 and updates ancestor dependency [bundlewatch](https://github.com/bundlewatch/bundlewatch). These dependencies need to be updated together.


Updates `axios` from 1.13.2 to 1.15.2
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)
- [Commits](axios/axios@v1.13.2...v1.15.2)

Updates `bundlewatch` from 0.4.1 to 0.4.2
- [Release notes](https://github.com/bundlewatch/bundlewatch/releases)
- [Commits](bundlewatch/bundlewatch@v0.4.1...v0.4.2)

---
updated-dependencies:
- dependency-name: axios
  dependency-version: 1.15.2
  dependency-type: indirect
- dependency-name: bundlewatch
  dependency-version: 0.4.2
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps-dev): bump postcss from 8.5.6 to 8.5.10 (#1039)

Bumps [postcss](https://github.com/postcss/postcss) from 8.5.6 to 8.5.10.
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.5.6...8.5.10)

---
updated-dependencies:
- dependency-name: postcss
  dependency-version: 8.5.10
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore: lock file

* chore(deps-dev): bump picomatch from 2.3.1 to 2.3.2 (#1022)

Bumps [picomatch](https://github.com/micromatch/picomatch) from 2.3.1 to 2.3.2.
- [Release notes](https://github.com/micromatch/picomatch/releases)
- [Changelog](https://github.com/micromatch/picomatch/blob/master/CHANGELOG.md)
- [Commits](micromatch/picomatch@2.3.1...2.3.2)

---
updated-dependencies:
- dependency-name: picomatch
  dependency-version: 2.3.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump handlebars from 4.7.8 to 4.7.9 (#1014)

Bumps [handlebars](https://github.com/handlebars-lang/handlebars.js) from 4.7.8 to 4.7.9.
- [Release notes](https://github.com/handlebars-lang/handlebars.js/releases)
- [Changelog](https://github.com/handlebars-lang/handlebars.js/blob/v4.7.9/release-notes.md)
- [Commits](handlebars-lang/handlebars.js@v4.7.8...v4.7.9)

---
updated-dependencies:
- dependency-name: handlebars
  dependency-version: 4.7.9
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore: lock file

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Tsachi Shlidor <tsachi.shlidor@cloudinary.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant