-
Notifications
You must be signed in to change notification settings - Fork 14.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add resolution to force dependencies to use patched lodash #15777
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
It would be best to see update the packages that use lodash but, in the interest of time and to avoid potentially breaking changes, this is a perfectly fine workaround.
The PR is likely OK to be merged with just subset of tests for default Python and Database versions without running the full matrix of tests, because it does not modify the core of Airflow. If the committers decide that the full tests matrix is needed, they will add the label 'full tests needed'. Then you should rebase to the latest master or amend the last commit of the PR, and push it with --force-with-lease. |
…apache#15777) Resolves [a known vulnerability](GHSA-35jh-r3h4-6jhm) in lodash. Lodash is an indirect dependency and not all of the the direct dependencies have been patched yet. This resolution forces the currently utilized `4.17.15`, `4.17.19`, and `4.17.20` versions to use the safe `4.17.21` patch. (cherry picked from commit 74c1ce0)
…apache#15777) Resolves [a known vulnerability](GHSA-35jh-r3h4-6jhm) in lodash. Lodash is an indirect dependency and not all of the the direct dependencies have been patched yet. This resolution forces the currently utilized `4.17.15`, `4.17.19`, and `4.17.20` versions to use the safe `4.17.21` patch. (cherry picked from commit 74c1ce0)
…#15777) Resolves [a known vulnerability](GHSA-35jh-r3h4-6jhm) in lodash. Lodash is an indirect dependency and not all of the the direct dependencies have been patched yet. This resolution forces the currently utilized `4.17.15`, `4.17.19`, and `4.17.20` versions to use the safe `4.17.21` patch.
Resolves a known vulnerability in lodash. Lodash is an indirect dependency and not all of the the direct dependencies have been patched yet. This resolution forces the currently utilized
4.17.15
,4.17.19
, and4.17.20
versions to use the safe4.17.21
patch.