Repository navigation
Conversation
- lodash 4.17.21 -> 4.18.1 (forced via resolutions; release-it pins it exactly) - handlebars 4.7.8 -> 4.7.10 - postcss 8.5.6 -> 8.5.29 Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
resolutions do not apply to consumers of the addon. Declaring these as direct dependencies raises the minimum versions that consumers resolve. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
The modal footer is a <form>, and since f005cd0 its submit button is a real submit button. The footer's submit handler never prevented the default action, so clicking it also performed a native form submission, reloading the page. In CI this showed up as a "Browser timeout exceeded" error in the bs-modal-simple tests. Prevent the default action in the footer before calling onSubmit, and drop the no-op onSubmit attribute on the submit button. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Gaurav0
force-pushed
the
gaurav/chore/SCF-2414-update-lodash-postcss-handlebars-security
branch
from
October 7, 2026 12:27
79e7396 to
7e252c6
Compare
testem 3.19.0 switched to the ESM-only execa ^9, and testem 3.20+ requires Node ^20.19. ember-try installs without the lockfile, so CI picked up testem 3.21 and failed on Node 16 with ERR_REQUIRE_ESM before running any tests. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@embroider/addon-shim 1.10.3 sets allowCachingPerBundle, so ember-focus-trap opts into ember-cli's per-bundle addon cache. ember-cli 3.28 then throws when the dummy app specifies an addon blacklist, which it does whenever FASTBOOT_DISABLED is set, breaking all Embroider ember-try scenarios. addon-shim 1.10.2 pulls in pkg-entry-points, whose 1.1.2 release requires Node >=20.19.5, so pin it to 1.1.1 to keep installs working on Node 16. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Gaurav0
force-pushed
the
gaurav/chore/SCF-2414-update-lodash-postcss-handlebars-security
branch
from
October 7, 2026 13:57
7e252c6 to
2531751
Compare
Gaurav0
marked this pull request as ready for review
October 7, 2026 14:06
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Resolves SCF-2414: upgrades the vulnerable
lodash,handlebarsandpostcssversions flagged by FOSSA. It also fixes a modal bug and the CI failures that were hiding it. Version bumped to 4.10.2.Security upgrades
None of these have known advisories at the new versions (GitHub Advisory Database).
yarn auditreports nothing for them, andnpm auditreports nothing for the packages themselves.All three are transitive dependencies. They come in through
ember-auto-import,@embroider/*andcss-loader.lodashgets aresolutionsentry becauserelease-itpins it exactly at4.17.21.resolutionsdon't reach consumers. To cover them, the three packages are added todependencieswith patched minimum versions (lodash ^4.18.1,handlebars ^4.7.10,postcss ^8.5.29). The addon doesn't import them directly. A consuming app whose lockfile already pins older copies for other dependents can still keep them. Downstream apps should runyarn upgrade lodash handlebars postcssafter picking up 4.10.2.The
ember-cli-htmlbars/semverresolution is removed. It made yarn 1 crash withInvariant Violation: should have a resolved reference, soyarn installfailed even onscf_master.Bug fix: modal footer submit reloaded the page
The modal footer is a
<form>. Since f005cd0 its primary button has beentype="submit", but nothing calledpreventDefault()on the form's submit event. Clicking the submit button of a<BsModalSimple @submitTitle=...>therefore calledonSubmitand natively submitted the form, which reloads the page. In CI this appeared as an intermittentBrowser timeout exceeded: 10sin the bs-modal-simple tests, because the reload killed the test runner.BsModal::Footeris now a small Glimmer component that prevents the default action before calling@onSubmit. A regression test covers this.CI fixes (ember-try scenarios)
ember-try installs without the lockfile, so all 36 scenario jobs picked up recent upstream releases that break on our Node 16 / ember-cli 3.28 setup. Both fixes are
resolutionsonly, so they don't affect consumers.testempinned to~3.18.0: testem 3.19+ uses ESM-onlyexeca, and testem 3.20+ requires Node 20, which causedERR_REQUIRE_ESMin the 30 non-Embroider scenarios.@embroider/addon-shimpinned to1.10.2: 1.10.3 opts v2 addons (hereember-focus-trap) into per-bundle addon caching. ember-cli 3.28 rejects that when the dummy app sets an addonblacklist, which it does underFASTBOOT_DISABLED. That broke the 6 Embroider scenarios.pkg-entry-pointspinned to1.1.1: addon-shim 1.10.2 pulls it in, and 1.1.2 requires Node ≥20.19.5, which would break the Node 16 install.Moving CI to Node 20+ would let these pins be dropped later.
Testing
yarn install --frozen-lockfile,yarn lint(0 errors),yarn build, andember test(526 passed, 10 skipped, 0 failed) all pass.yarn nodetestpassed on Node 22.Follow-up outside this PR
yarn auditstill reports advisories in other packages, mostly dev tooling (got,form-data,@octokit/*,semver, …). They are out of scope here.🤖 Generated with Claude Code