Skip to content

Commit a3309c5

Browse files
authored
Merge pull request #914 from telefonicaid/dependabot/npm_and_yarn/underscore-1.13.8
Bump underscore from 1.12.1 to 1.13.8
2 parents 82c785b + 35ab67f commit a3309c5

2 files changed

Lines changed: 3 additions & 2 deletions

File tree

CHANGES_NEXT_RELEASE

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1,2 @@
1-
- Upgrade express from 4.21.2 to 4.22.1
1+
- Upgrade express dep from 4.21.2 to 4.22.1
2+
- Upgrade underscore dep from 1.12.1 to 1.13.8 due to CVE-2026-27601

package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -72,7 +72,7 @@
7272
"logops": "2.1.2",
7373
"mqtt": "5.13.0",
7474
"sinon": "~6.1.0",
75-
"underscore": "1.12.1"
75+
"underscore": "1.13.8"
7676
},
7777
"husky": {
7878
"hooks": {

0 commit comments

Comments
 (0)