Skip to content

chore(deps): bump underscore from 1.13.7 to 1.13.8 to address CVE-2026-27601#431

Open
skukhtichev wants to merge 3 commits into
jupyter:mainfrom
skukhtichev:security_underscore_update
Open

chore(deps): bump underscore from 1.13.7 to 1.13.8 to address CVE-2026-27601#431
skukhtichev wants to merge 3 commits into
jupyter:mainfrom
skukhtichev:security_underscore_update

Conversation

@skukhtichev

Copy link
Copy Markdown

Summary

Updates underscore dependency from 1.13.7 to 1.13.8 to address security vulnerability CVE-2026-27601.

Changes

Bump underscore from ~1.13.7 to ~1.13.8 in package.json.

Security

Fixes CVE-2026-27601.

@krassowski

Copy link
Copy Markdown
Member

I suppose the lock file would need to be updated too?

@skukhtichev

Copy link
Copy Markdown
Author

@krassowski I regenerated the yarn.lock file. To maintain the security scope, I regenerated only the underscore changes without affecting other dependencies.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants