fix(deps): update dependency lodash to v4.17.23 [security]#1080
Open
renovate[bot] wants to merge 1 commit intomainfrom
Open
fix(deps): update dependency lodash to v4.17.23 [security]#1080renovate[bot] wants to merge 1 commit intomainfrom
renovate[bot] wants to merge 1 commit intomainfrom
Conversation
Plan Result (@infrastructure/shareable-lists-api-production) |
3d4884a to
d8a46e2
Compare
Plan Result (@infrastructure/pocket-event-bridge-production)
|
d8a46e2 to
bcc5952
Compare
Plan Result (@infrastructure/shares-api-production)
|
bcc5952 to
04f4fc8
Compare
Plan Result (@infrastructure/user-api-production)
|
04f4fc8 to
aca8bf2
Compare
Plan Result (@infrastructure/v3-proxy-api-production) |
aca8bf2 to
a7cca0e
Compare
a7cca0e to
2446134
Compare
❌ Plan Result (@infrastructure/user-list-search-production) |
Plan Result (@infrastructure/image-api-production) |
a54e931 to
87a543f
Compare
87a543f to
820929b
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.17.21→4.17.23GitHub Vulnerability Alerts
CVE-2025-13465
Impact
Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the
_.unsetand_.omitfunctions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes.The issue permits deletion of properties but does not allow overwriting their original behavior.
Patches
This issue is patched on 4.17.23.
Release Notes
lodash/lodash (lodash)
v4.17.23Compare Source
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.