Skip to content

fix(deps): update dependency lodash to v4.17.21 [security]#236

Merged
mmkal merged 3 commits intomainfrom
renovate/npm-lodash-vulnerability
May 9, 2021
Merged

fix(deps): update dependency lodash to v4.17.21 [security]#236
mmkal merged 3 commits intomainfrom
renovate/npm-lodash-vulnerability

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented May 9, 2021

WhiteSource Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
lodash (source) 4.17.20 -> 4.17.21 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2021-23337

lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.


Release Notes

lodash/lodash

v4.17.21

Compare Source


Configuration

📅 Schedule: "" (UTC).

🚦 Automerge: Enabled.

♻️ Rebasing: Renovate will not automatically rebase this PR, because other commits have been found.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box.

This PR has been generated by WhiteSource Renovate. View repository job log here.

@codecov-commenter
Copy link

codecov-commenter commented May 9, 2021

Codecov Report

Merging #236 (0373066) into main (eb3b412) will not change coverage.
The diff coverage is n/a.

Impacted file tree graph

@@            Coverage Diff            @@
##              main      #236   +/-   ##
=========================================
  Coverage   100.00%   100.00%           
=========================================
  Files           41        41           
  Lines          725       725           
  Branches       121       121           
=========================================
  Hits           725       725           

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update eb3b412...0373066. Read the comment docs.

@mmkal mmkal merged commit c7a416c into main May 9, 2021
@mmkal mmkal deleted the renovate/npm-lodash-vulnerability branch May 9, 2021 21:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants