NIFI-9460: Update Lodash to 4.17.21#5605
Merged
mtien-apache merged 2 commits intoapache:mainfrom Dec 16, 2021
Merged
Conversation
sardell
commented
Dec 15, 2021
| @@ -18,28 +18,28 @@ | |||
| "dependencies": { | |||
Contributor
Author
There was a problem hiding this comment.
Although there appear to be many changes in this file, most are a result of npm re-ordering the dependencies alphabetically after removing lodash-core and installing lodash@4.17.21 (this happens whenever an npm command is run that changes the package.json file).
Contributor
|
Reviewing |
mtien-apache
approved these changes
Dec 16, 2021
Contributor
mtien-apache
left a comment
There was a problem hiding this comment.
Thanks for the PR @sardell! LGTM. Verified npm audit does not list lodash as a vulnerability.
krisztina-zsihovszki
pushed a commit
to krisztina-zsihovszki/nifi
that referenced
this pull request
Jun 28, 2022
* NIFI-9460: update lodash transitive dep in registry * NIFI-9460: use lodash instead of lodash-core Merged apache#5605 into main.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Thank you for submitting a contribution to Apache NiFi.
Please provide a short description of the PR here:
Description of PR
NIFI-9460: Update Lodash version to 4.17.21
This PR bumps lodash to 4.17.21 in nifi-registry. In addition, I changed the NiFi UI deps to use lodash instead of lodash-core. I did this because lodash-core is still using an older version of lodash and there is no indication they will update to utilize the 4.17.21 release (see current open issues).
In order to streamline the review of the contribution we ask you
to ensure the following steps have been taken:
For all changes:
Is there a JIRA ticket associated with this PR? Is it referenced
in the commit message?
Does your PR title start with NIFI-XXXX where XXXX is the JIRA number you are trying to resolve? Pay particular attention to the hyphen "-" character.
Has your PR been rebased against the latest commit within the target branch (typically
main)?Is your initial contribution a single, squashed commit? Additional commits in response to PR reviewer feedback should be made on this branch and pushed to allow change tracking. Do not
squashor use--forcewhen pushing to allow for clean monitoring of changes.For code changes:
mvn -Pcontrib-check clean installat the rootnififolder?LICENSEfile, including the mainLICENSEfile undernifi-assembly?NOTICEfile, including the mainNOTICEfile found undernifi-assembly?.displayNamein addition to .name (programmatic access) for each of the new properties?For documentation related changes:
Note:
Please ensure that once the PR is submitted, you check GitHub Actions CI for build issues and submit an update to your PR as soon as possible.