Skip to content

Commit f0d3d87

Browse files
committed
EUREKA-883: Bump lodash 4.17.21 -> 4.17.23 fix CVE-2025-13465
https://folio-org.atlassian.net/browse/EUREKA-883 Bump lodash from 4.17.21 to 4.17.23 in resolutions section of package.json. This fixes * GHSA-xxjr-mmjv-4gpg CVE-2025-13465 - lodash prototype pollution
1 parent e49ea6a commit f0d3d87

2 files changed

Lines changed: 5 additions & 4 deletions

File tree

package.json

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -116,6 +116,7 @@
116116
"colors": "1.4.0",
117117
"dompurify": "^3.2.7",
118118
"final-form": "^4.20.4",
119+
"lodash": "^4.17.23",
119120
"minimist": "^1.2.3",
120121
"moment": "~2.29.0",
121122
"qs": "^6.14.1",

yarn.lock

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -6260,10 +6260,10 @@ lodash.groupby@^4.6.0:
62606260
resolved "https://registry.yarnpkg.com/lodash.groupby/-/lodash.groupby-4.6.0.tgz#0b08a1dcf68397c397855c3239783832df7403d1"
62616261
integrity sha512-5dcWxm23+VAoz+awKmBaiBvzox8+RqMgFhi7UvX9DHZr2HdxHXM/Wrf8cfKpsW37RNrvtPn6hSwNqurSILbmJw==
62626262

6263-
lodash@^4.16.4, lodash@^4.17.11, lodash@^4.17.15, lodash@^4.17.19, lodash@^4.17.20, lodash@^4.17.21, lodash@^4.17.4, lodash@^4.17.5:
6264-
version "4.17.21"
6265-
resolved "https://registry.yarnpkg.com/lodash/-/lodash-4.17.21.tgz#679591c564c3bffaae8454cf0b3df370c3d6911c"
6266-
integrity sha512-v2kDEe57lecTulaDIuNTPy3Ry4gLGJ6Z1O3vE1krgXZNrsQ+LFTGHVxVjcXPs17LhbZVGedAJv8XZ1tvj5FvSg==
6263+
lodash@^4.16.4, lodash@^4.17.11, lodash@^4.17.15, lodash@^4.17.19, lodash@^4.17.20, lodash@^4.17.21, lodash@^4.17.23, lodash@^4.17.4, lodash@^4.17.5:
6264+
version "4.18.1"
6265+
resolved "https://registry.yarnpkg.com/lodash/-/lodash-4.18.1.tgz#ff2b66c1f6326d59513de2407bf881439812771c"
6266+
integrity sha512-dMInicTPVE8d1e5otfwmmjlxkZoUpiVLwyeTdUsi/Caj/gfzzblBcCE5sRHV/AsjuCmxWrte2TNGSYuCeCq+0Q==
62676267

62686268
log-symbols@^4.1.0:
62696269
version "4.1.0"

0 commit comments

Comments
 (0)