Skip to content

[SCF-2414] update lodash, postcss, handlebars [SECURITY] - #4

Open
Gaurav0 wants to merge 6 commits into
scf_masterfrom
gaurav/chore/SCF-2414-update-lodash-postcss-handlebars-security
Open

Gaurav0 wants to merge 6 commits into
scf_masterfrom
gaurav/chore/SCF-2414-update-lodash-postcss-handlebars-security

Conversation

@Gaurav0

@Gaurav0 Gaurav0 commented Oct 6, 2026 •

Copy link
Copy Markdown

Resolves SCF-2414: upgrades the vulnerable lodash, handlebars and postcss versions flagged by FOSSA. It also fixes a modal bug and the CI failures that were hiding it. Version bumped to 4.10.2.

Security upgrades

Package Before After Findings cleared
lodash 4.17.21 4.18.1 CVE-2026-4800, CVE-2026-2950, CVE-2025-13465
handlebars 4.7.8 4.7.10 CVE-2026-33937, -33938, -33939, -33940, -33941, -33916
postcss 8.5.6 8.5.29 CVE-2026-45623, -73646, -41305, -69153

None of these have known advisories at the new versions (GitHub Advisory Database). yarn audit reports nothing for them, and npm audit reports nothing for the packages themselves.

All three are transitive dependencies. They come in through ember-auto-import, @embroider/* and css-loader.

  • This repo's lockfile: lodash gets a resolutions entry because release-it pins it exactly at 4.17.21.
  • Consuming apps: resolutions don't reach consumers. To cover them, the three packages are added to dependencies with patched minimum versions (lodash ^4.18.1, handlebars ^4.7.10, postcss ^8.5.29). The addon doesn't import them directly. A consuming app whose lockfile already pins older copies for other dependents can still keep them. Downstream apps should run yarn upgrade lodash handlebars postcss after picking up 4.10.2.

The ember-cli-htmlbars/semver resolution is removed. It made yarn 1 crash with Invariant Violation: should have a resolved reference, so yarn install failed even on scf_master.

Bug fix: modal footer submit reloaded the page

The modal footer is a <form>. Since f005cd0 its primary button has been type="submit", but nothing called preventDefault() on the form's submit event. Clicking the submit button of a <BsModalSimple @submitTitle=...> therefore called onSubmit and natively submitted the form, which reloads the page. In CI this appeared as an intermittent Browser timeout exceeded: 10s in the bs-modal-simple tests, because the reload killed the test runner.

BsModal::Footer is now a small Glimmer component that prevents the default action before calling @onSubmit. A regression test covers this.

CI fixes (ember-try scenarios)

ember-try installs without the lockfile, so all 36 scenario jobs picked up recent upstream releases that break on our Node 16 / ember-cli 3.28 setup. Both fixes are resolutions only, so they don't affect consumers.

  • testem pinned to ~3.18.0: testem 3.19+ uses ESM-only execa, and testem 3.20+ requires Node 20, which caused ERR_REQUIRE_ESM in the 30 non-Embroider scenarios.
  • @embroider/addon-shim pinned to 1.10.2: 1.10.3 opts v2 addons (here ember-focus-trap) into per-bundle addon caching. ember-cli 3.28 rejects that when the dummy app sets an addon blacklist, which it does under FASTBOOT_DISABLED. That broke the 6 Embroider scenarios.
  • pkg-entry-points pinned to 1.1.1: addon-shim 1.10.2 pulls it in, and 1.1.2 requires Node ≥20.19.5, which would break the Node 16 install.

Moving CI to Node 20+ would let these pins be dropped later.

Testing

  • CI is fully green: all 39 jobs, including every ember-try scenario.
  • Locally on Node 16 and Node 22: yarn install --frozen-lockfile, yarn lint (0 errors), yarn build, and ember test (526 passed, 10 skipped, 0 failed) all pass. yarn nodetest passed on Node 22.

Follow-up outside this PR

  • Rescan with FOSSA and update the linked COMP findings.
  • Bump downstream SCF apps to 4.10.2 and refresh their lockfiles (see above).
  • yarn audit still reports advisories in other packages, mostly dev tooling (got, form-data, @octokit/*, semver, …). They are out of scope here.

🤖 Generated with Claude Code

Gaurav0 and others added 2 commits October 6, 2026 15:41
- lodash 4.17.21 -> 4.18.1 (forced via resolutions; release-it pins it exactly)
- handlebars 4.7.8 -> 4.7.10
- postcss 8.5.6 -> 8.5.29

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
resolutions do not apply to consumers of the addon. Declaring these as
direct dependencies raises the minimum versions that consumers resolve.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
The modal footer is a <form>, and since f005cd0 its submit button is a
real submit button. The footer's submit handler never prevented the
default action, so clicking it also performed a native form submission,
reloading the page. In CI this showed up as a "Browser timeout exceeded"
error in the bs-modal-simple tests.

Prevent the default action in the footer before calling onSubmit, and
drop the no-op onSubmit attribute on the submit button.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Gaurav0
Gaurav0 force-pushed the gaurav/chore/SCF-2414-update-lodash-postcss-handlebars-security branch from 79e7396 to 7e252c6 Compare October 7, 2026 12:27
Gaurav0 and others added 3 commits October 7, 2026 09:55
testem 3.19.0 switched to the ESM-only execa ^9, and testem 3.20+
requires Node ^20.19. ember-try installs without the lockfile, so CI
picked up testem 3.21 and failed on Node 16 with ERR_REQUIRE_ESM before
running any tests.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@embroider/addon-shim 1.10.3 sets allowCachingPerBundle, so ember-focus-trap
opts into ember-cli's per-bundle addon cache. ember-cli 3.28 then throws
when the dummy app specifies an addon blacklist, which it does whenever
FASTBOOT_DISABLED is set, breaking all Embroider ember-try scenarios.

addon-shim 1.10.2 pulls in pkg-entry-points, whose 1.1.2 release requires
Node >=20.19.5, so pin it to 1.1.1 to keep installs working on Node 16.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@Gaurav0
Gaurav0 force-pushed the gaurav/chore/SCF-2414-update-lodash-postcss-handlebars-security branch from 7e252c6 to 2531751 Compare October 7, 2026 13:57
@Gaurav0
Gaurav0 marked this pull request as ready for review October 7, 2026 14:06
@Gaurav0
Gaurav0 requested review from a team, AndrewHYi and Joeu October 7, 2026 14:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant