Skip to content

chore(deps): bump lodash to ^4.17.23#5702

Merged
lucas-zimerman merged 1 commit intomainfrom
antonis/bump-lodash
Feb 24, 2026
Merged

chore(deps): bump lodash to ^4.17.23#5702
lucas-zimerman merged 1 commit intomainfrom
antonis/bump-lodash

Conversation

@antonis
Copy link
Copy Markdown
Contributor

@antonis antonis commented Feb 24, 2026

Summary

  • Adds a resolutions entry to force lodash to >=4.17.23
  • Fixes prototype pollution vulnerability in _.unset and _.omit (affected range: >= 4.0.0, <= 4.17.22)

Dependabot alerts

Test plan

  • yarn install resolves lodash to 4.17.23
  • yarn build passes
  • yarn test passes

🤖 Generated with Claude Code

Adds a yarn resolution to force lodash to >=4.17.23, patching the
prototype pollution vulnerability in _.unset and _.omit (currently
at 4.17.21, affected range >= 4.0.0, <= 4.17.22).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@antonis antonis added the ready-to-merge Triggers the full CI test suite label Feb 24, 2026
@github-actions
Copy link
Copy Markdown
Contributor

github-actions bot commented Feb 24, 2026

Semver Impact of This PR

None (no version bump detected)

📋 Changelog Preview

This is how your changes will appear in the changelog.
Entries from this PR are highlighted with a left border (blockquote style).


  • chore(deps): bump lodash to ^4.17.23 by antonis in #5702
  • chore(deps): bump getsentry/craft from 2.21.4 to 2.21.7 by dependabot in #5694
  • chore(deps): bump getsentry/craft/.github/workflows/changelog-preview.yml from 2.21.4 to 2.21.7 by dependabot in #5695
  • chore(deps): update CLI to v3.2.2 by github-actions in #5692
  • chore(deps): bump github/codeql-action from 4.32.3 to 4.32.4 by dependabot in #5693
  • chore(deps): update Maestro to v2.2.0 by github-actions in #5691
  • chore(deps): update Cocoa SDK to v9.5.0 by github-actions in #5685
  • chore(deps): update Android SDK Stubs to v8.33.0 by github-actions in #5697
  • chore(deps): update Android SDK to v8.33.0 by github-actions in #5684
  • chore(deps): update Sentry Android Gradle Plugin to v6.1.0 by github-actions in #5687
  • Ref(CI): Add android sdk version check by lucas-zimerman in #5686

🤖 This preview updates automatically when you update the PR.

@github-actions
Copy link
Copy Markdown
Contributor

iOS (legacy) Performance metrics 🚀

  Plain With Sentry Diff
Startup time 1207.23 ms 1218.17 ms 10.94 ms
Size 3.38 MiB 4.78 MiB 1.40 MiB

Baseline results on branch: main

Startup times

Revision Plain With Sentry Diff
c08359e+dirty 1235.25 ms 1233.96 ms -1.29 ms
90e7cb3+dirty 1206.61 ms 1209.46 ms 2.84 ms
4e6d7d7+dirty 1206.72 ms 1214.19 ms 7.47 ms
4997892+dirty 1217.98 ms 1222.57 ms 4.60 ms
8e653ac+dirty 1218.63 ms 1223.88 ms 5.24 ms
6bd9054+dirty 1212.20 ms 1217.89 ms 5.70 ms
d751a5d+dirty 1215.57 ms 1220.56 ms 4.99 ms
2f9fb30+dirty 1189.51 ms 1190.71 ms 1.20 ms
8334e91+dirty 1205.45 ms 1210.90 ms 5.45 ms
f8d19f8+dirty 1203.98 ms 1209.74 ms 5.77 ms

App size

Revision Plain With Sentry Diff
c08359e+dirty 2.63 MiB 3.81 MiB 1.18 MiB
90e7cb3+dirty 3.41 MiB 4.58 MiB 1.17 MiB
4e6d7d7+dirty 3.38 MiB 4.60 MiB 1.22 MiB
4997892+dirty 3.38 MiB 4.60 MiB 1.22 MiB
8e653ac+dirty 2.63 MiB 4.01 MiB 1.38 MiB
6bd9054+dirty 3.41 MiB 4.67 MiB 1.25 MiB
d751a5d+dirty 2.63 MiB 3.98 MiB 1.34 MiB
2f9fb30+dirty 3.41 MiB 4.59 MiB 1.18 MiB
8334e91+dirty 3.38 MiB 4.78 MiB 1.40 MiB
f8d19f8+dirty 3.44 MiB 4.59 MiB 1.15 MiB

@github-actions
Copy link
Copy Markdown
Contributor

Android (legacy) Performance metrics 🚀

  Plain With Sentry Diff
Startup time 400.59 ms 415.32 ms 14.73 ms
Size 43.75 MiB 48.46 MiB 4.71 MiB

Baseline results on branch: main

Startup times

Revision Plain With Sentry Diff
df1f7df+dirty 442.64 ms 427.16 ms -15.48 ms
a483f9f+dirty 396.82 ms 453.28 ms 56.46 ms
a0b15d6 423.06 ms 437.77 ms 14.71 ms
7091004+dirty 416.11 ms 423.90 ms 7.79 ms
5526494 440.84 ms 448.36 ms 7.52 ms
8a4ce6f 422.88 ms 408.33 ms -14.55 ms
526494a+dirty 422.80 ms 438.90 ms 16.10 ms
60cd796+dirty 445.84 ms 492.45 ms 46.61 ms
3bd3f0d+dirty 447.21 ms 472.31 ms 25.10 ms
769e11c+dirty 409.15 ms 446.06 ms 36.91 ms

App size

Revision Plain With Sentry Diff
df1f7df+dirty 43.75 MiB 48.08 MiB 4.33 MiB
a483f9f+dirty 43.75 MiB 48.41 MiB 4.66 MiB
a0b15d6 17.75 MiB 20.15 MiB 2.41 MiB
7091004+dirty 43.75 MiB 47.99 MiB 4.23 MiB
5526494 17.75 MiB 19.68 MiB 1.93 MiB
8a4ce6f 17.75 MiB 19.68 MiB 1.94 MiB
526494a+dirty 43.75 MiB 47.99 MiB 4.24 MiB
60cd796+dirty 43.75 MiB 48.07 MiB 4.32 MiB
3bd3f0d+dirty 17.75 MiB 19.70 MiB 1.95 MiB
769e11c+dirty 43.75 MiB 48.41 MiB 4.66 MiB

@antonis antonis mentioned this pull request Feb 24, 2026
@antonis antonis marked this pull request as ready for review February 24, 2026 12:13
@github-actions
Copy link
Copy Markdown
Contributor

iOS (new) Performance metrics 🚀

  Plain With Sentry Diff
Startup time 1217.86 ms 1215.56 ms -2.29 ms
Size 3.38 MiB 4.78 MiB 1.40 MiB

Baseline results on branch: main

Startup times

Revision Plain With Sentry Diff
c08359e+dirty 1200.59 ms 1211.81 ms 11.22 ms
90e7cb3+dirty 1212.61 ms 1213.80 ms 1.19 ms
4e6d7d7+dirty 1204.87 ms 1212.74 ms 7.86 ms
4997892+dirty 1212.09 ms 1212.46 ms 0.37 ms
8e653ac+dirty 1215.46 ms 1220.20 ms 4.75 ms
6bd9054+dirty 1207.02 ms 1199.27 ms -7.76 ms
d751a5d+dirty 1212.22 ms 1217.94 ms 5.71 ms
2f9fb30+dirty 1219.06 ms 1223.38 ms 4.32 ms
8334e91+dirty 1220.96 ms 1224.70 ms 3.74 ms
f8d19f8+dirty 1212.06 ms 1219.53 ms 7.47 ms

App size

Revision Plain With Sentry Diff
c08359e+dirty 3.19 MiB 4.38 MiB 1.19 MiB
90e7cb3+dirty 3.41 MiB 4.58 MiB 1.17 MiB
4e6d7d7+dirty 3.38 MiB 4.60 MiB 1.22 MiB
4997892+dirty 3.38 MiB 4.60 MiB 1.22 MiB
8e653ac+dirty 3.19 MiB 4.58 MiB 1.39 MiB
6bd9054+dirty 3.41 MiB 4.67 MiB 1.25 MiB
d751a5d+dirty 3.19 MiB 4.54 MiB 1.36 MiB
2f9fb30+dirty 3.41 MiB 4.59 MiB 1.18 MiB
8334e91+dirty 3.38 MiB 4.78 MiB 1.40 MiB
f8d19f8+dirty 3.44 MiB 4.59 MiB 1.15 MiB

@github-actions
Copy link
Copy Markdown
Contributor

Android (new) Performance metrics 🚀

  Plain With Sentry Diff
Startup time 392.00 ms 468.98 ms 76.98 ms
Size 43.94 MiB 49.33 MiB 5.39 MiB

Baseline results on branch: main

Startup times

Revision Plain With Sentry Diff
8d89cc9+dirty 357.69 ms 415.79 ms 58.10 ms
90afdd3+dirty 367.79 ms 404.84 ms 37.05 ms
ff5a06a+dirty 438.29 ms 476.00 ms 37.71 ms
8ff81c0+dirty 392.47 ms 431.52 ms 39.05 ms
8d0a325+dirty 430.13 ms 476.52 ms 46.39 ms
170d5ea+dirty 348.79 ms 406.94 ms 58.15 ms
6c36ba5+dirty 367.14 ms 426.80 ms 59.66 ms
817b2c1+dirty 379.06 ms 404.96 ms 25.90 ms
90edad7+dirty 372.57 ms 398.83 ms 26.26 ms
136effd+dirty 451.30 ms 450.87 ms -0.43 ms

App size

Revision Plain With Sentry Diff
8d89cc9+dirty 7.15 MiB 8.41 MiB 1.26 MiB
90afdd3+dirty 7.15 MiB 8.43 MiB 1.28 MiB
ff5a06a+dirty 43.94 MiB 48.87 MiB 4.93 MiB
8ff81c0+dirty 43.94 MiB 48.87 MiB 4.93 MiB
8d0a325+dirty 43.94 MiB 48.91 MiB 4.97 MiB
170d5ea+dirty 7.15 MiB 8.42 MiB 1.27 MiB
6c36ba5+dirty 43.94 MiB 49.27 MiB 5.33 MiB
817b2c1+dirty 43.94 MiB 49.22 MiB 5.29 MiB
90edad7+dirty 7.15 MiB 8.43 MiB 1.28 MiB
136effd+dirty 43.94 MiB 48.81 MiB 4.88 MiB

@lucas-zimerman lucas-zimerman merged commit 1595a60 into main Feb 24, 2026
120 of 137 checks passed
@lucas-zimerman lucas-zimerman deleted the antonis/bump-lodash branch February 24, 2026 14:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ready-to-merge Triggers the full CI test suite

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants