• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

pillarjs / hbs / 32831631690
92%

Build:
DEFAULT BRANCH: master
Ran 25 Aug 2026 09:23AM UTC
Jobs 0
Files 0
Run time –
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

pending completion
32831631690

push

github

web-flow
Merge commit from fork

* tests: assert async helper output is HTML-escaped by {{...}}

Ref: https://github.com/pillarjs/hbs/security/advisories/GHSA-rg36-rxv9-2m9q

* fix: escape async helper values at the render substitution sites

Wrap async-helper placeholder substitution with handlebars.Utils.escapeExpression at the three render paths (cached, uncached, layout) so `{{...}}` honors its documented HTML-escape contract for async helpers, matching sync-helper behavior. Consumers who need raw HTML output can opt in via `new handlebars.SafeString(value)` in the callback.

Ref: https://github.com/pillarjs/hbs/security/advisories/GHSA-rg36-rxv9-2m9q

Co-Authored-By: EQSTLab <148991397+EQSTLab@users.noreply.github.com>

* fix: enhance render function to accept options and improve async helper caching

* fix: preserve legacy output for nullish async helper values

---------

Co-authored-by: EQSTLab <148991397+EQSTLab@users.noreply.github.com>
Co-authored-by: Sebastian Beltran <bjohansebas@gmail.com>
Source Files on build 32831631690
Detailed source file information is not available for this build.
  • Back to Repo
  • Github Actions Build #32831631690
  • d8849867 on github
  • Prev Build on master (#32735985622)
  • Next Build on master (#32831822419)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc