Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(security): Bump lodash version to 4.17.21 #1004

Merged
merged 3 commits into from
Mar 3, 2021
Merged

fix(security): Bump lodash version to 4.17.21 #1004

merged 3 commits into from
Mar 3, 2021

Conversation

matt-primrose
Copy link
Contributor

@matt-primrose matt-primrose commented Mar 2, 2021

Description

Fixes #1003
Bump lodash version from 4.17.20 to 4.17.21

To-do list

  • I have added tests for what I changed.
  • This pull request is ready to merge.

@coveralls
Copy link

coveralls commented Mar 2, 2021

Coverage Status

Coverage remained the same at 100.0% when pulling 864436e on matt-primrose:patch-1 into 4645318 on express-validator:master.

Copy link
Member

@fedeci fedeci left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We should update also package-lock.json.

@fedeci fedeci added the PR: dependencies Pull requests that update a dependency file label Mar 2, 2021
@matt-primrose
Copy link
Contributor Author

package-lock.json has been updated to lodash version 4.17.21 as well

Copy link
Member

@fedeci fedeci left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks!

@fedeci fedeci merged commit b1ab453 into express-validator:master Mar 3, 2021
@jcass8695
Copy link

Hey, when will this patch be released?

@matt-primrose matt-primrose deleted the patch-1 branch April 23, 2021 14:09
@gustavohenke
Copy link
Member

Done @JCass45, published as v6.10.1! Sorry for the delay.

@jcass8695
Copy link

@gustavohenke Thanks man! 🙏🏻

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
PR: dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

High and medium severity issues found in lodash 4.17.20
5 participants