Skip to content

Commit 8953c37

Browse files
Merge pull request #302 from Staffbase/fix/dependabot-97-lodash-cve-2026-4800
fix: upgrade lodash to 4.18.1 to patch CVE-2026-4800 (Dependabot #97)
2 parents fafd347 + eefe37a commit 8953c37

2 files changed

Lines changed: 5 additions & 4 deletions

File tree

package.json

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -93,6 +93,7 @@
9393
},
9494
"resolutions": {
9595
"cross-spawn": "^7.0.6",
96+
"lodash": "^4.18.0",
9697
"minimatch": "^5.1.8",
9798
"wrap-ansi": "^7.0.0",
9899
"semver": "^7.3.2"

yarn.lock

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -4439,10 +4439,10 @@ lodash.upperfirst@^4.3.1:
44394439
resolved "https://registry.yarnpkg.com/lodash.upperfirst/-/lodash.upperfirst-4.3.1.tgz#1365edf431480481ef0d1c68957a5ed99d49f7ce"
44404440
integrity sha512-sReKOYJIJf74dhJONhU4e0/shzi1trVbSWDOhKYE5XV2O+H7Sb2Dihwuc7xWxVl+DgFPyTqIN3zMfT9cq5iWDg==
44414441

4442-
lodash@^4.17.15, lodash@^4.17.21, lodash@~4.17.21:
4443-
version "4.17.21"
4444-
resolved "https://registry.yarnpkg.com/lodash/-/lodash-4.17.21.tgz#679591c564c3bffaae8454cf0b3df370c3d6911c"
4445-
integrity sha512-v2kDEe57lecTulaDIuNTPy3Ry4gLGJ6Z1O3vE1krgXZNrsQ+LFTGHVxVjcXPs17LhbZVGedAJv8XZ1tvj5FvSg==
4442+
lodash@^4.17.15, lodash@^4.17.21, lodash@^4.18.0, lodash@~4.17.21:
4443+
version "4.18.1"
4444+
resolved "https://registry.yarnpkg.com/lodash/-/lodash-4.18.1.tgz#ff2b66c1f6326d59513de2407bf881439812771c"
4445+
integrity sha512-dMInicTPVE8d1e5otfwmmjlxkZoUpiVLwyeTdUsi/Caj/gfzzblBcCE5sRHV/AsjuCmxWrte2TNGSYuCeCq+0Q==
44464446

44474447
loglevel@^1.8.1:
44484448
version "1.9.2"

0 commit comments

Comments
 (0)