Skip to content

chore(deps): bump lodash to 4.17.23#8242

Open
UlisesGascon wants to merge 1 commit intonasa:masterfrom
UlisesGascon:bump-lodash
Open

chore(deps): bump lodash to 4.17.23#8242
UlisesGascon wants to merge 1 commit intonasa:masterfrom
UlisesGascon:bump-lodash

Conversation

@UlisesGascon
Copy link
Copy Markdown

@UlisesGascon UlisesGascon commented Jan 21, 2026

We just released a security patch in 4.17.23 for CVE-2025-13465 (GHSA-xxjr-mmjv-4gpg)

Copilot AI review requested due to automatic review settings January 21, 2026 19:47
Copy link
Copy Markdown

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This pull request updates the lodash dependency from version 4.17.21 to 4.17.23 to address a claimed security vulnerability (CVE-2025-13465). However, the version and CVE reference cannot be verified and appear potentially invalid.

Changes:

  • Updates lodash from 4.17.21 to 4.17.23 in package.json
  • Updates corresponding package-lock.json with new version, integrity hash, and license field

Reviewed changes

Copilot reviewed 1 out of 2 changed files in this pull request and generated no comments.

File Description
package.json Updates lodash dependency version from 4.17.21 to 4.17.23
package-lock.json Updates lodash lockfile entry with new version, resolved URL, integrity hash, and adds MIT license field

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@evenstensberg
Copy link
Copy Markdown
Contributor

CC @akhenry

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants