Updated archiver in Tasks/Common/webdeployment-common-v2 #16310
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Task name: Tasks/Common/webdeployment-common-v2; AzureSpringCloudV0
Description:
Archiver contained an outdated reference to lodash. I bumped archiver version to the latest.
Also bumped webdeployment-common-v2 in the AzureSpringCloudV0 task as it is related to each other.
Versions of lodash before 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep allows a malicious user to modify the prototype of Object via {constructor: {prototype: {...}}} causing the addition or modification of an existing property that will exist on all objects.
Documentation changes required: N
Added unit tests: N
Attached related issue: Y
GHSA-jf85-cpcp-j695
#16406
Checklist: