Skip to content

Chore: Upgrade lodash to fix securityy vulnerability#216

Open
SbsCruz wants to merge 1 commit into
mainfrom
chore/lodash-upgrade
Open

Chore: Upgrade lodash to fix securityy vulnerability#216
SbsCruz wants to merge 1 commit into
mainfrom
chore/lodash-upgrade

Conversation

@SbsCruz
Copy link
Copy Markdown
Collaborator

@SbsCruz SbsCruz commented May 26, 2026

This PR upgrades lodash to version 4.18.1 to fix Code Injection via _.template imports key names

Related Security Alert: Dependabot#225

@SbsCruz SbsCruz requested review from mateopozor02 and suany0805 May 26, 2026 15:50
Comment thread yarn.lock
version: 4.17.21
resolution: "lodash@npm:4.17.21"
checksum: 10/c08619c038846ea6ac754abd6dd29d2568aa705feb69339e836dfa8d8b09abbb2f859371e86863eda41848221f9af43714491467b5b0299122431e202bb0c532
version: 4.18.1
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

why is the main dependency not being upgraded in here? 🤔

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants