Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Framework: Bump Lodash dependencies to 4.17.14 #16567

Merged
merged 3 commits into from Jul 12, 2019

Conversation

@aduth
Copy link
Member

commented Jul 12, 2019

This pull request seeks to bump Lodash from 4.17.11 to 4.17.14, for all included packages, and pinned for all dependencies which depend on Lodash. It includes a script override for the default-registered copy shipped with WordPress.

Testing Instructions:

Verify there are no warning messages or local changes after running npm install.

Verify the editor loads correctly, and that running lodash.VERSION in your browser developer tools yields a value of 4.17.14.

@aduth aduth merged commit 174b8f2 into master Jul 12, 2019

1 of 21 checks passed

Filter merged Filter merged
Details
Filter merged Filter merged
Details
Filter merged Filter merged
Details
Filter merged Filter merged
Details
Filter merged Filter merged
Details
Filter merged Filter merged
Details
Filter merged Filter merged
Details
Filter merged Filter merged
Details
Filter merged Filter merged
Details
Filter merged Filter merged
Details
Filter merged Filter merged
Details
Filter merged Filter merged
Details
Filter merged Filter merged
Details
Filter merged Filter merged
Details
Filter merged Filter merged
Details
Filter merged Filter merged
Details
Filter merged Filter merged
Details
Filter merged Filter merged
Details
Filter merged Filter merged
Details
Filter merged Filter merged
Details
Travis CI - Pull Request Build Passed
Details

@aduth aduth deleted the bump/lodash-4-17-x branch Jul 12, 2019

mcsf added a commit that referenced this pull request Jul 19, 2019

Framework: Bump Lodash dependencies to 4.17.14 (#16567)
* Framework: Refresh package-lock.json by latest NPM

See: https://github.com/WordPress/gutenberg/pull/16404/files#r303057081

* Framework: Bump Lodash to 4.17.4 for all packages

* Framework: Pin vulnerable dependencies to updated minors

jg314 added a commit to jg314/gutenberg that referenced this pull request Jul 19, 2019

Framework: Bump Lodash dependencies to 4.17.14 (WordPress#16567)
* Framework: Refresh package-lock.json by latest NPM

See: https://github.com/WordPress/gutenberg/pull/16404/files#r303057081

* Framework: Bump Lodash to 4.17.4 for all packages

* Framework: Pin vulnerable dependencies to updated minors

@aduth aduth added this to the Gutenberg 6.2 milestone Jul 24, 2019

sbardian added a commit to sbardian/gutenberg that referenced this pull request Jul 29, 2019

Framework: Bump Lodash dependencies to 4.17.14 (WordPress#16567)
* Framework: Refresh package-lock.json by latest NPM

See: https://github.com/WordPress/gutenberg/pull/16404/files#r303057081

* Framework: Bump Lodash to 4.17.4 for all packages

* Framework: Pin vulnerable dependencies to updated minors
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
You can’t perform that action at this time.