Skip to content

fix: bump lodash resolution to 4.18.1 to address CVEs #70 #71#169

Merged
maximizeIT merged 1 commit intomainfrom
copilot/investigate-dependabot-alerts-lodash
Apr 8, 2026
Merged

fix: bump lodash resolution to 4.18.1 to address CVEs #70 #71#169
maximizeIT merged 1 commit intomainfrom
copilot/investigate-dependabot-alerts-lodash

Conversation

Copy link
Copy Markdown
Contributor

Copilot AI commented Apr 8, 2026

lodash <= 4.17.23 is affected by two vulnerabilities: high-severity code injection via _.template imports key names, and moderate prototype pollution via array path bypass in _.unset/_.omit. Both are patched in 4.18.0; 4.18.1 is used as 4.18.0 was deprecated by the maintainers.

Changes

  • package.json: Update resolutions.lodash from 4.17.234.18.1
  • yarn.lock: Regenerated to reflect the new resolution

…#71

Co-authored-by: GitHub Copilot <copilot@noreply.github.com>

Agent-Logs-Url: https://github.com/Staffbase/create-staffbase-plugin-nodejs/sessions/2764984f-c76e-40be-b281-718eb1d9bb8e

Co-authored-by: maximizeIT <8626039+maximizeIT@users.noreply.github.com>
@maximizeIT maximizeIT marked this pull request as ready for review April 8, 2026 08:13
@maximizeIT maximizeIT requested a review from a team as a code owner April 8, 2026 08:13
@maximizeIT maximizeIT enabled auto-merge April 8, 2026 08:13
@maximizeIT maximizeIT merged commit 0807f60 into main Apr 8, 2026
7 checks passed
@maximizeIT maximizeIT deleted the copilot/investigate-dependabot-alerts-lodash branch April 8, 2026 09:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants