Commit 7446b90
Upgrade lodash/lodash-es to 4.18.1 (CVE-2026-4800)
Summary:
Upgrade transitive dependency lodash from 4.17.21/4.17.23 to 4.18.1 and lodash-es
from 4.17.21 to 4.18.1 to remediate CVE-2026-4800 (Improper Control of Generation
of Code / Code Injection).
Updated lodash/lodash-es entries in 3 yarn.lock files:
- xplat/js/tools/react-fox/yarn.lock (lodash 4.17.21 → 4.18.1)
- xplat/js/tools/react-fox/apps/playground/yarn.lock (lodash 4.17.23 → 4.18.1)
- xplat/js/tools/metro/website/yarn.lock (lodash-es 4.17.21 → 4.18.1)
No package.json changes needed.
Reviewed By: Bellardia
Differential Revision: D102241929
fbshipit-source-id: b9a4d3ff16b2e74ea115d7954e6eebc3c0514b341 parent 40d9ccf commit 7446b90
1 file changed
Lines changed: 3 additions & 3 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
6548 | 6548 | | |
6549 | 6549 | | |
6550 | 6550 | | |
6551 | | - | |
6552 | | - | |
6553 | | - | |
| 6551 | + | |
| 6552 | + | |
| 6553 | + | |
6554 | 6554 | | |
6555 | 6555 | | |
6556 | 6556 | | |
| |||
0 commit comments