Skip to content

Commit 7446b90

Browse files
sandeep3028meta-codesync[bot]
authored andcommitted
Upgrade lodash/lodash-es to 4.18.1 (CVE-2026-4800)
Summary: Upgrade transitive dependency lodash from 4.17.21/4.17.23 to 4.18.1 and lodash-es from 4.17.21 to 4.18.1 to remediate CVE-2026-4800 (Improper Control of Generation of Code / Code Injection). Updated lodash/lodash-es entries in 3 yarn.lock files: - xplat/js/tools/react-fox/yarn.lock (lodash 4.17.21 → 4.18.1) - xplat/js/tools/react-fox/apps/playground/yarn.lock (lodash 4.17.23 → 4.18.1) - xplat/js/tools/metro/website/yarn.lock (lodash-es 4.17.21 → 4.18.1) No package.json changes needed. Reviewed By: Bellardia Differential Revision: D102241929 fbshipit-source-id: b9a4d3ff16b2e74ea115d7954e6eebc3c0514b34
1 parent 40d9ccf commit 7446b90

1 file changed

Lines changed: 3 additions & 3 deletions

File tree

website/yarn.lock

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -6548,9 +6548,9 @@ locate-path@^7.1.0:
65486548
p-locate "^6.0.0"
65496549

65506550
lodash-es@^4.17.21:
6551-
version "4.17.21"
6552-
resolved "https://registry.yarnpkg.com/lodash-es/-/lodash-es-4.17.21.tgz#43e626c46e6591b7750beb2b50117390c609e3ee"
6553-
integrity sha512-mKnC+QJ9pWVzv+C4/U3rRsHapFfHvQFoFB92e52xeyGMcX6/OlIl78je1u8vePzYZSkkogMPJ2yjxxsb89cxyw==
6551+
version "4.18.1"
6552+
resolved "https://registry.yarnpkg.com/lodash-es/-/lodash-es-4.18.1.tgz#b962eeb80d9d983a900bf342961fb7418ca10b1d"
6553+
integrity sha512-J8xewKD/Gk22OZbhpOVSwcs60zhd95ESDwezOFuA3/099925PdHJ7OFHNTGtajL3AlZkykD32HykiMo+BIBI8A==
65546554

65556555
lodash.debounce@^4.0.8:
65566556
version "4.0.8"

0 commit comments

Comments
 (0)