chore(deps): update dependency lodash to v4.17.23 [security]#1371
chore(deps): update dependency lodash to v4.17.23 [security]#1371renovate[bot] wants to merge 1 commit intomasterfrom
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #1371 +/- ##
=======================================
Coverage 18.35% 18.35%
=======================================
Files 454 454
Lines 74865 74865
Branches 1594 1594
=======================================
Hits 13743 13743
Misses 61122 61122
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
Playwright test resultsDetails
Failed testschromium-setup › auth.setup.ts › authenticate as user - Skipped testschromium › pages/myOrganization.test.ts › MyOrganization › Invitation Management: should display all required elements - |
7443ca2 to
ef21cee
Compare
53da7ad to
e44e507
Compare
e44e507 to
d31838c
Compare
This PR contains the following updates:
4.17.21→4.17.23GitHub Vulnerability Alerts
CVE-2025-13465
Impact
Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the
_.unsetand_.omitfunctions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes.The issue permits deletion of properties but does not allow overwriting their original behavior.
Patches
This issue is patched on 4.17.23.
Release Notes
lodash/lodash (lodash)
v4.17.23Compare Source
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.