Skip to content

⚠️ SECURITY-#23: Fix lodash vulnerabilities#24

Merged
FernandoCelmer merged 1 commit intodevelopfrom
feature/23
Apr 10, 2026
Merged

⚠️ SECURITY-#23: Fix lodash vulnerabilities#24
FernandoCelmer merged 1 commit intodevelopfrom
feature/23

Conversation

@FernandoCelmer
Copy link
Copy Markdown
Member

Summary

  • Add overrides in package.json to force lodash@>=4.18.0 for all transitive dependencies
  • Regenerate package-lock.json — lodash updated from 4.17.21 to 4.18.1
  • Resolve Dependabot alerts #36, #61, #62

Dependabot Alerts Resolved

Alert Severity Issue
#62 High Code Injection via _.template
#61 Medium Prototype Pollution via _.unset/_.omit
#36 Medium Prototype Pollution in _.unset/_.omit

Closes #23

@FernandoCelmer FernandoCelmer merged commit 3dba80d into develop Apr 10, 2026
1 check failed
@FernandoCelmer FernandoCelmer deleted the feature/23 branch April 10, 2026 17:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant