Skip to content

[Snyk] Upgrade lodash from 4.17.20 to 4.17.21#4

Merged
hashim21223445 merged 1 commit intomainfrom
snyk-upgrade-fcb03f734f4c1bf930dbdaf636aef61d
May 4, 2025
Merged

[Snyk] Upgrade lodash from 4.17.20 to 4.17.21#4
hashim21223445 merged 1 commit intomainfrom
snyk-upgrade-fcb03f734f4c1bf930dbdaf636aef61d

Conversation

@snyk-io
Copy link

@snyk-io snyk-io bot commented Jan 6, 2025

snyk-top-banner

Snyk has created this PR to upgrade lodash from 4.17.20 to 4.17.21.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 1 version ahead of your current version.

  • The recommended version was released 4 years ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Code Injection
SNYK-JS-LODASH-1040724
84 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-1018905
84 Proof of Concept
Release notes
Package name: lodash from lodash GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

@semanticdiff-com
Copy link

semanticdiff-com bot commented Jan 6, 2025

Review changes with  SemanticDiff

Changed Files
File Status
  package.json  0% smaller

@hashim21223445 hashim21223445 self-requested a review May 4, 2025 20:59
@hashim21223445 hashim21223445 self-assigned this May 4, 2025
@hashim21223445 hashim21223445 added merge when passing Merge the PR automatically once all status checks have passed patch version Automatically create a new patch version tag after PR is merged minor version Automatically create a new minor version tag after PR is merged major version Automatically create a new major version tag after PR is merged labels May 4, 2025
@hashim21223445 hashim21223445 added this to the Fait milestone May 4, 2025
@hashim21223445 hashim21223445 merged commit ce06e8f into main May 4, 2025
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

major version Automatically create a new major version tag after PR is merged merge when passing Merge the PR automatically once all status checks have passed minor version Automatically create a new minor version tag after PR is merged patch version Automatically create a new patch version tag after PR is merged

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant