WhisperX tag archive

#npm_security

This page collects WhisperX intelligence signals tagged #npm_security. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-03-30 15:27:36 · GitHub Issues

1. GitHub Security Fix: Critical Handlebars Injection CVE & 25 Production Vulnerabilities Eliminated

A critical security remediation has been executed, eliminating 25 production dependency vulnerabilities—including a critical Handlebars.js injection CVE—and securing the build pipeline. The fix directly removed the `auto-changelog` devDependency, which was the source of the critical CVE and four related high-severity i...