Commit 56a8191
fix: bump lodash to 4.18.1 to remediate CVE-2026-4800 (#25)
lodash <4.18.0 allows code injection via unsanitised options.imports key
names in _.template(). Fixed in 4.18.0. Resolves ENG-14004.
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>1 parent 83cb8c2 commit 56a8191
2 files changed
Lines changed: 6 additions & 6 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
9 | 9 | | |
10 | 10 | | |
11 | 11 | | |
12 | | - | |
| 12 | + | |
13 | 13 | | |
14 | 14 | | |
15 | 15 | | |
16 | 16 | | |
17 | 17 | | |
18 | | - | |
| 18 | + | |
19 | 19 | | |
20 | 20 | | |
21 | 21 | | |
| |||
0 commit comments