Skip to content

Conversation

@derrickmehaffy
Copy link
Member

Signed-off-by: Derrick Mehaffy derrickmehaffy@gmail.com

What does it do?

Fixed missing lodash upgrade in the i18n plugin

Why is it needed?

Prototype pollution fix when we upgraded the lodash version: #9990

How to test it?

Run a yarn audit and notice missing vuln reports

Related issue(s)/PR(s)

N/A

Signed-off-by: Derrick Mehaffy <derrickmehaffy@gmail.com>
@derrickmehaffy derrickmehaffy added the source: dependencies Source is dependency problem label Jun 23, 2021
@derrickmehaffy derrickmehaffy requested a review from a team June 23, 2021 21:25
@codecov
Copy link

codecov bot commented Jun 23, 2021

Codecov Report

Merging #10538 (1247875) into master (6f7e0c2) will not change coverage.
The diff coverage is n/a.

Impacted file tree graph

@@           Coverage Diff           @@
##           master   #10538   +/-   ##
=======================================
  Coverage   58.01%   58.01%           
=======================================
  Files         185      185           
  Lines        6431     6431           
  Branches     1400     1400           
=======================================
  Hits         3731     3731           
  Misses       2236     2236           
  Partials      464      464           
Flag Coverage Δ
front ∅ <ø> (∅)
unit 58.01% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.


Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 6f7e0c2...1247875. Read the comment docs.

@alexandrebodin alexandrebodin merged commit 22ece10 into master Jun 24, 2021
@alexandrebodin alexandrebodin deleted the fix/lodashvuln branch June 24, 2021 07:05
@derrickmehaffy
Copy link
Member Author

This pull request has been mentioned on Strapi Community Forum. There might be relevant details there:

https://forum.strapi.io/t/strapi-3-6-5-vulnerabilities/5995/2

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

source: dependencies Source is dependency problem

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants