Skip to content

VULN UPGRADE: patch: lodash, prettier [azure]#1066

Closed
campaigner-prod[bot] wants to merge 1 commit into
masterfrom
engraver-auto-version-upgrade/minorpatch/npm/azure/0-1770923952
Closed

VULN UPGRADE: patch: lodash, prettier [azure]#1066
campaigner-prod[bot] wants to merge 1 commit into
masterfrom
engraver-auto-version-upgrade/minorpatch/npm/azure/0-1770923952

Conversation

@campaigner-prod

Copy link
Copy Markdown
Contributor

Summary: Security update — 2 packages upgraded (patch changes only)

Manifests changed:

  • azure (npm)

Updates

Package From To Type Vulnerabilities Fixed
lodash 4.17.21 4.17.23 patch 2 MODERATE
prettier 3.7.3 3.7.4 patch -

Packages marked with "-" are updated due to dependency constraints.


Security Details

ℹ️ Other Vulnerabilities (2)
Package CVE Severity Summary Unsafe Version Fixed In
lodash GHSA-xxjr-mmjv-4gpg MODERATE Lodash has Prototype Pollution Vulnerability in _.unset and _.omit functions 4.17.21 4.17.23
lodash CVE-2025-13465 MODERATE - 4.17.21 -

Review Checklist

Standard review:

  • Review changes for compatibility with your code
  • Check for breaking changes in release notes
  • Run tests locally or wait for CI

Update Mode: Vulnerability Remediation

🤖 Generated by DataDog Automated Dependency Management System

@dd-prapprover dd-prapprover Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR has been automatically approved by the DD PR Approver bot.

@campaigner-prod campaigner-prod Bot closed this Mar 1, 2026
@campaigner-prod campaigner-prod Bot deleted the engraver-auto-version-upgrade/minorpatch/npm/azure/0-1770923952 branch March 1, 2026 14:10
@DataDog DataDog deleted a comment from dd-prapprover Bot Mar 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant