Commit 226d47b
fix(security): bump lodash 4.17.23 → 4.18.1 in examples/js (ENG-14277)
Adds overrides entry to block GHSA-r5fr-rjxr-66jc (CVE-2026-4800, CVSS HIGH):
lodash _.template code injection via options.imports key names, fixed in 4.18.0.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>1 parent 015a918 commit 226d47b
2 files changed
Lines changed: 4 additions & 3 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
26 | 26 | | |
27 | 27 | | |
28 | 28 | | |
| 29 | + | |
29 | 30 | | |
30 | 31 | | |
31 | 32 | | |
0 commit comments