Skip to content

chore(deps): update dependency lodash to v4.17.23 [security]#116

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-lodash-vulnerability
Open

chore(deps): update dependency lodash to v4.17.23 [security]#116
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-lodash-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Jan 23, 2026

Copy link
Copy Markdown

This PR contains the following updates:

Package Change Age Confidence
lodash (source) 4.17.214.17.23 age confidence

Lodash has Prototype Pollution Vulnerability in _.unset and _.omit functions

CVE-2025-13465 / GHSA-xxjr-mmjv-4gpg

More information

Details

Impact

Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes.

The issue permits deletion of properties but does not allow overwriting their original behavior.

Patches

This issue is patched on 4.17.23.

Severity

  • CVSS Score: 6.9 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H/E:P

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

lodash/lodash (lodash)

v4.17.23

Compare Source


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@vercel

vercel Bot commented Jan 23, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
hygraph-next-enterprise Ready Ready Preview, Comment Jun 7, 2026 9:40am

Request Review

@github-actions

Copy link
Copy Markdown

Seems you are using me but didn't get OPENAI_API_KEY seted in Variables/Secrets for this repo. you could follow readme for more information

@renovate renovate Bot changed the title chore(deps): update dependency lodash to v4.17.23 [security] chore(deps): update dependency lodash to v4.17.23 [security] - autoclosed Mar 31, 2026
@renovate renovate Bot closed this Mar 31, 2026
@renovate renovate Bot deleted the renovate/npm-lodash-vulnerability branch March 31, 2026 21:16
@renovate renovate Bot changed the title chore(deps): update dependency lodash to v4.17.23 [security] - autoclosed chore(deps): update dependency lodash to v4.17.23 [security] Apr 1, 2026
@renovate renovate Bot reopened this Apr 1, 2026
@renovate renovate Bot force-pushed the renovate/npm-lodash-vulnerability branch from da099aa to 535a8bf Compare April 1, 2026 14:40
@github-actions

github-actions Bot commented Apr 1, 2026

Copy link
Copy Markdown

Seems you are using me but didn't get OPENAI_API_KEY seted in Variables/Secrets for this repo. you could follow readme for more information

@renovate renovate Bot changed the title chore(deps): update dependency lodash to v4.17.23 [security] chore(deps): update dependency lodash to v4.18.1 [security] Apr 2, 2026
@renovate renovate Bot force-pushed the renovate/npm-lodash-vulnerability branch from 535a8bf to 8733f4c Compare April 2, 2026 18:38
@github-actions

github-actions Bot commented Apr 2, 2026

Copy link
Copy Markdown

Seems you are using me but didn't get OPENAI_API_KEY seted in Variables/Secrets for this repo. you could follow readme for more information

@renovate renovate Bot changed the title chore(deps): update dependency lodash to v4.18.1 [security] chore(deps): update dependency lodash to v4.18.1 [security] - autoclosed Apr 15, 2026
@renovate renovate Bot closed this Apr 15, 2026
@renovate renovate Bot changed the title chore(deps): update dependency lodash to v4.18.1 [security] - autoclosed chore(deps): update dependency lodash to v4.18.1 [security] Apr 16, 2026
@renovate renovate Bot reopened this Apr 16, 2026
@renovate renovate Bot force-pushed the renovate/npm-lodash-vulnerability branch 2 times, most recently from 8733f4c to ae2e561 Compare April 16, 2026 15:43
@github-actions

Copy link
Copy Markdown

Seems you are using me but didn't get OPENAI_API_KEY seted in Variables/Secrets for this repo. you could follow readme for more information

@renovate renovate Bot changed the title chore(deps): update dependency lodash to v4.18.1 [security] chore(deps): update dependency lodash to v4.17.23 [security] May 10, 2026
@renovate renovate Bot force-pushed the renovate/npm-lodash-vulnerability branch from ae2e561 to 73a1cb0 Compare May 10, 2026 08:57
@github-actions

Copy link
Copy Markdown

Seems you are using me but didn't get OPENAI_API_KEY seted in Variables/Secrets for this repo. you could follow readme for more information

@renovate renovate Bot force-pushed the renovate/npm-lodash-vulnerability branch from 73a1cb0 to 4b644ca Compare May 10, 2026 13:29
@renovate renovate Bot changed the title chore(deps): update dependency lodash to v4.17.23 [security] chore(deps): update dependency lodash to v4.18.1 [security] May 10, 2026
@github-actions

Copy link
Copy Markdown

Seems you are using me but didn't get OPENAI_API_KEY seted in Variables/Secrets for this repo. you could follow readme for more information

@renovate renovate Bot force-pushed the renovate/npm-lodash-vulnerability branch from 4b644ca to a6c1bfc Compare June 7, 2026 09:37
@renovate renovate Bot changed the title chore(deps): update dependency lodash to v4.18.1 [security] chore(deps): update dependency lodash to v4.17.23 [security] Jun 7, 2026
@renovate

renovate Bot commented Jun 7, 2026

Copy link
Copy Markdown
Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: yarn.lock
[09:37:38.092] INFO (773): Installing tool node@24.16.0...
[09:37:38.338] ERROR (773): download failed
    run: 3
    err: {
      "type": "HTTPError",
      "message": "Request failed with status code 504 (Gateway Time-out): GET https://github.com/containerbase/node-prebuild/releases/download/24.16.0/node-24.16.0-x86_64.tar.xz",
      "stack":
          HTTPError: Request failed with status code 504 (Gateway Time-out): GET https://github.com/containerbase/node-prebuild/releases/download/24.16.0/node-24.16.0-x86_64.tar.xz
              at Request._onResponseBase (file:///snapshot/dist/app/main-BTOx0EXc.js:33507:22)
              at Request._onResponse (file:///snapshot/dist/app/main-BTOx0EXc.js:33568:15)
              at ClientRequest.<anonymous> (file:///snapshot/dist/app/main-BTOx0EXc.js:33594:9)
              at Object.onceWrapper (node:events:631:26)
              at ClientRequest.emit (node:events:521:24)
              at ClientRequest.emit (node:domain:489:12)
              at HTTPParser.parserOnIncomingClient (node:_http_client:798:27)
              at HTTPParser.parserOnHeadersComplete (node:_http_common:125:17)
              at TLSSocket.socketOnData (node:_http_client:633:22)
              at TLSSocket.emit (node:events:509:28)
      "name": "HTTPError",
      "code": "ERR_NON_2XX_3XX_RESPONSE",
      "timings": {
        "start": 1780825058332,
        "socket": 1780825058333,
        "lookup": 1780825058333,
        "connect": 1780825058333,
        "secureConnect": 1780825058333,
        "upload": 1780825058333,
        "response": 1780825058336,
        "end": 1780825058337,
        "phases": {
          "wait": 1,
          "dns": 1,
          "tcp": 4,
          "tls": 6,
          "request": 0,
          "firstByte": 3,
          "download": 1,
          "total": 5
        }
      },
      "options": {
        "agent": {},
        "decompress": true,
        "timeout": {},
        "prefixUrl": "",
        "ignoreInvalidCookies": false,
        "context": {},
        "hooks": {
          "init": [],
          "beforeRequest": [],
          "beforeError": [],
          "beforeRedirect": [],
          "beforeRetry": [],
          "beforeCache": [],
          "afterResponse": []
        },
        "followRedirect": true,
        "maxRedirects": 10,
        "throwHttpErrors": true,
        "username": "",
        "password": "",
        "http2": false,
        "allowGetBody": false,
        "copyPipedHeaders": false,
        "headers": {
          "user-agent": "containerbase/14.10.21 node/24.16.0 (https://github.com/containerbase)",
          "accept-encoding": "gzip, deflate, br, zstd"
        },
        "methodRewriting": false,
        "retry": {
          "limit": 2,
          "methods": [
            "GET",
            "PUT",
            "HEAD",
            "DELETE",
            "OPTIONS",
            "TRACE"
          ],
          "statusCodes": [
            408,
            413,
            429,
            500,
            502,
            503,
            504,
            521,
            522,
            524
          ],
          "errorCodes": [
            "ETIMEDOUT",
            "ECONNRESET",
            "EADDRINUSE",
            "ECONNREFUSED",
            "EPIPE",
            "ENOTFOUND",
            "ENETUNREACH",
            "EAI_AGAIN"
          ],
          "backoffLimit": null,
          "noise": 100,
          "enforceRetryRules": true
        },
        "method": "GET",
        "cacheOptions": {},
        "https": {},
        "resolveBodyOnly": false,
        "isStream": true,
        "responseType": "text",
        "url": "https://github.com/containerbase/node-prebuild/releases/download/24.16.0/node-24.16.0-x86_64.tar.xz",
        "pagination": {
          "countLimit": null,
          "backoff": 0,
          "requestLimit": 10000,
          "stackAllItems": false
        },
        "setHost": true,
        "enableUnixSockets": false,
        "strictContentLength": true
      }
    }
[09:37:38.405] ERROR (773): download failed
[09:37:38.405] FATAL (773): Install tool node failed in 329ms.

@github-actions

github-actions Bot commented Jun 7, 2026

Copy link
Copy Markdown

Seems you are using me but didn't get OPENAI_API_KEY seted in Variables/Secrets for this repo. you could follow readme for more information

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants