build(deps): bump lodash from 4.17.23 to 4.18.1 - #2357
Conversation
|
@dependabot rebase |
Bumps [lodash](https://github.com/lodash/lodash) from 4.17.23 to 4.18.1. - [Release notes](https://github.com/lodash/lodash/releases) - [Commits](lodash/lodash@4.17.23...4.18.1) --- updated-dependencies: - dependency-name: lodash dependency-version: 4.18.1 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
a18b7c0 to
fa62caa
Compare
Review: transitive build-time dep, closes 2 advisories, one live call site, build passes — safe to merge.
Not a direct dependency: absent from What it fixes
Both list 4.17.23 as vulnerable. Silent behaviour change: 4.18.1 is why this is safe, not 4.18.0. 4.18.0 shipped a Why nothing breaks
Verified
Also ran 4.18.1 in isolation against our exact call patterns ( Caveats
Follow-ups (non-blocking)
|
Bumps lodash from 4.17.23 to 4.18.1.
Release notes
Sourced from lodash's releases.
Commits
cb0b9b9release(patch): bump main to 4.18.1 (#6177)75535f5chore: prune stale advisory refs (#6170)62e91bcdocs: remove n_ Node.js < 6 REPL note from README (#6165)59be2derelease(minor): bump to 4.18.0 (#6161)af63457fix: broken tests for _.template 879aaa91073a76fix: linting issues879aaa9fix: validate imports keys in _.templatefe8d32efix: block prototype pollution in baseUnset via constructor/prototype traversal18ba0a3refactor(fromPairs): use baseAssignValue for consistent assignment (#6153)b819080ci: add dist sync validation workflow (#6137)