Skip to content

Bump lodash 4.18.1 to address CVEs#5744

Open
cmalonzo wants to merge 4 commits intomicrosoft:mainfrom
cmalonzo:lodash/4.18.0
Open

Bump lodash 4.18.1 to address CVEs#5744
cmalonzo wants to merge 4 commits intomicrosoft:mainfrom
cmalonzo:lodash/4.18.0

Conversation

@cmalonzo
Copy link
Copy Markdown
Contributor

@cmalonzo cmalonzo commented Apr 2, 2026

Summary

Bump lodash to 4.18.0 to address CVEs:

Build affected packages — the commit touches api-extractor, heft-jest-plugin, npm-check-fork, and localization-plugin-test-02

How it was tested

  1. rush install
  2. confirm we're using new lodash version
  3. run build: rush build rush build --to api-extractor --to heft-jest-plugin --to npm-check-fork
  4. run tests: rush test --to api-extractor --to heft-jest-plugin

@cmalonzo cmalonzo changed the title Bump lodash 4.18.0 to address CVEs Bump lodash 4.18.1 to address CVEs Apr 3, 2026
@cmalonzo cmalonzo requested a review from TheLarkInn as a code owner April 3, 2026 03:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Needs triage

Development

Successfully merging this pull request may close these issues.

3 participants