Skip to content

fix(deps): Bump rollup-plugin-license to fix lodash vulnerabilities#20636

Merged
chargome merged 2 commits intodevelopfrom
fix/dependabot-alert-1281
May 4, 2026
Merged

fix(deps): Bump rollup-plugin-license to fix lodash vulnerabilities#20636
chargome merged 2 commits intodevelopfrom
fix/dependabot-alert-1281

Conversation

@chargome
Copy link
Copy Markdown
Member

@chargome chargome commented May 4, 2026

Summary

  • Bumps rollup-plugin-license from 3.3.1 → 3.7.1
  • This updates the lodash constraint from ~4.17.21 to ^4.17.21, allowing resolution to patched lodash 4.18.x
  • Removes orphaned lodash@4.17.23 lockfile entry
  • Fixes Dependabot alert 1281 (CVE-2026-4800, code injection via _.template)
  • Fixes Dependabot alert 1280 (CVE-2026-2950, prototype pollution via _.unset/_.omit)

🤖 Generated with Claude Code

…d prototype pollution

Bumps rollup-plugin-license 3.3.1 → 3.7.1 which updates its lodash
constraint from ~4.17.21 to ^4.17.21, allowing resolution to patched
lodash 4.18.x. Removes orphaned lodash@4.17.23 lockfile entry.

Fixes Dependabot alerts #1281 (CVE-2026-4800) and #1280 (CVE-2026-2950).

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Copy link
Copy Markdown

@cursor cursor Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit a7ceadd. Configure here.

Comment thread yarn.lock Outdated
package-name-regex "~2.0.6"
spdx-expression-validate "~2.0.0"
spdx-satisfies "~5.0.1"
rollup-plugin-license@3.7.1:
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lockfile key missing caret for rollup-plugin-license range

High Severity

The yarn.lock entry key is rollup-plugin-license@3.7.1 (exact version) but package.json specifies "^3.7.1" (caret range). In Yarn v1, the lockfile key must match the range string from the consumer. Every other ^-ranged rollup-plugin-* dependency correctly has the ^ in its lockfile key (e.g., rollup-plugin-cleanup@^3.2.1). This mismatch means Yarn won't find a locked resolution for ^3.7.1, causing yarn install --frozen-lockfile to fail or a regular yarn install to re-resolve the dependency, defeating the purpose of the lockfile.

Additional Locations (1)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit a7ceadd. Configure here.

@chargome chargome marked this pull request as draft May 4, 2026 11:12
@chargome chargome self-assigned this May 4, 2026
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented May 4, 2026

size-limit report 📦

Path Size % Change Change
@sentry/browser 26.31 kB - -
@sentry/browser - with treeshaking flags 24.8 kB - -
@sentry/browser (incl. Tracing) 44.2 kB - -
@sentry/browser (incl. Tracing + Span Streaming) 46.42 kB - -
@sentry/browser (incl. Tracing, Profiling) 49.16 kB - -
@sentry/browser (incl. Tracing, Replay) 83.58 kB - -
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags 73.04 kB - -
@sentry/browser (incl. Tracing, Replay with Canvas) 88.26 kB - -
@sentry/browser (incl. Tracing, Replay, Feedback) 100.87 kB - -
@sentry/browser (incl. Feedback) 43.47 kB - -
@sentry/browser (incl. sendFeedback) 31.12 kB - -
@sentry/browser (incl. FeedbackAsync) 36.21 kB - -
@sentry/browser (incl. Metrics) 27.62 kB - -
@sentry/browser (incl. Logs) 27.75 kB - -
@sentry/browser (incl. Metrics & Logs) 28.45 kB - -
@sentry/react 28.05 kB - -
@sentry/react (incl. Tracing) 46.42 kB - -
@sentry/vue 31.18 kB - -
@sentry/vue (incl. Tracing) 46.04 kB - -
@sentry/svelte 26.34 kB - -
CDN Bundle 28.91 kB - -
CDN Bundle (incl. Tracing) 46.95 kB - -
CDN Bundle (incl. Logs, Metrics) 30.34 kB - -
CDN Bundle (incl. Tracing, Logs, Metrics) 48.06 kB - -
CDN Bundle (incl. Replay, Logs, Metrics) 69.41 kB - -
CDN Bundle (incl. Tracing, Replay) 84.11 kB - -
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) 85.16 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback) 89.91 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) 91.01 kB - -
CDN Bundle - uncompressed 84.72 kB - -
CDN Bundle (incl. Tracing) - uncompressed 140.31 kB - -
CDN Bundle (incl. Logs, Metrics) - uncompressed 88.92 kB - -
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed 143.77 kB - -
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed 212.86 kB - -
CDN Bundle (incl. Tracing, Replay) - uncompressed 258.11 kB - -
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed 261.56 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed 271.81 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed 275.25 kB - -
@sentry/nextjs (client) 48.92 kB - -
@sentry/sveltekit (client) 44.67 kB - -
@sentry/node-core 59.13 kB +0.02% +8 B 🔺
@sentry/node 170.42 kB +0.01% +9 B 🔺
@sentry/node - without tracing 97 kB +0.01% +8 B 🔺
@sentry/aws-serverless 113.85 kB +0.03% +32 B 🔺
@sentry/cloudflare (withSentry) - minified 165.2 kB - -
@sentry/cloudflare (withSentry) 417.71 kB - -

View base workflow run

@chargome chargome marked this pull request as ready for review May 4, 2026 12:10
@chargome chargome merged commit 96955b9 into develop May 4, 2026
255 checks passed
@chargome chargome deleted the fix/dependabot-alert-1281 branch May 4, 2026 12:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants