Skip to content

Commit e629eb0

Browse files
committed
fix(security): address remaining Dependabot alerts
- Upgrade lodash 4.17.21 → 4.17.23 in scripts and evals packages - Remove stale package-lock.json files in sdk/test directories that had outdated transitive dependencies (diff, ai) Closes remaining 8 Dependabot alerts
1 parent 2678045 commit e629eb0

File tree

6 files changed

+4
-917
lines changed

6 files changed

+4
-917
lines changed

bun.lock

Lines changed: 2 additions & 6 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

evals/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -39,7 +39,7 @@
3939
"@oclif/parser": "^3.8.17",
4040
"async": "^3.2.6",
4141
"diff": "^8.0.2",
42-
"lodash": "4.17.21",
42+
"lodash": "4.17.23",
4343
"p-limit": "^6.2.0",
4444
"zod": "^4.2.1"
4545
},

scripts/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@
2424
"@ai-sdk/openai-compatible": "^1.0.19",
2525
"@codebuff/bigquery": "workspace:*",
2626
"@codebuff/common": "workspace:*",
27-
"lodash": "4.17.21"
27+
"lodash": "4.17.23"
2828
},
2929
"devDependencies": {
3030
"@types/bun": "^1.3.5",

sdk/test/cjs-compatibility/package-lock.json

Lines changed: 0 additions & 313 deletions
This file was deleted.

0 commit comments

Comments
 (0)