Skip to content

chore: bump lodash to 4.18.1 and @types/lodash to 4.17.24#994

Merged
rzhao271 merged 1 commit intomainfrom
copilot/bump-lodash
Apr 6, 2026
Merged

chore: bump lodash to 4.18.1 and @types/lodash to 4.17.24#994
rzhao271 merged 1 commit intomainfrom
copilot/bump-lodash

Conversation

Copy link
Copy Markdown
Contributor

Copilot AI commented Apr 6, 2026

Bumps lodash from ^4.17.23 to ^4.18.1 and @types/lodash from ^4.14.104 to ^4.17.24.

The previous version of lodash (≤4.17.23) has a known vulnerability: Code Injection via _.template imports key names (patched in 4.18.0).

@rzhao271 rzhao271 marked this pull request as ready for review April 6, 2026 18:37
@rzhao271 rzhao271 added this to the 1.116.0 milestone Apr 6, 2026
@rzhao271 rzhao271 enabled auto-merge (squash) April 6, 2026 18:37
@rzhao271 rzhao271 merged commit b682f5d into main Apr 6, 2026
18 of 19 checks passed
@rzhao271 rzhao271 deleted the copilot/bump-lodash branch April 6, 2026 19:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants