-
-
Notifications
You must be signed in to change notification settings - Fork 1.8k
chore(deps): update dependency lodash to v4.17.23 [security] #5777
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: next
Are you sure you want to change the base?
Conversation
|
Deploying egg-v3 with
|
| Latest commit: |
7206674
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://258cd57b.egg-v3.pages.dev |
| Branch Preview URL: | https://renovate-npm-lodash-vulnerab.egg-v3.pages.dev |
|
Important Review skippedBot user detected. To trigger a single review, invoke the You can disable this status message by setting the Comment |
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
Deploying egg with
|
| Latest commit: |
7206674
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://adf0278a.egg-cci.pages.dev |
| Branch Preview URL: | https://renovate-npm-lodash-vulnerab.egg-cci.pages.dev |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## next #5777 +/- ##
==========================================
- Coverage 87.57% 87.55% -0.02%
==========================================
Files 563 563
Lines 10940 10940
Branches 1242 1242
==========================================
- Hits 9581 9579 -2
- Misses 1275 1277 +2
Partials 84 84 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
This PR contains the following updates:
4.17.21→4.17.23GitHub Vulnerability Alerts
CVE-2025-13465
Impact
Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the
_.unsetand_.omitfunctions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes.The issue permits deletion of properties but does not allow overwriting their original behavior.
Patches
This issue is patched on 4.17.23.
Release Notes
lodash/lodash (lodash)
v4.17.23Compare Source
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.