diff --git a/ghost/core/package.json b/ghost/core/package.json index 2794ed6636c..c779d9ea0cc 100644 --- a/ghost/core/package.json +++ b/ghost/core/package.json @@ -240,7 +240,7 @@ "xml": "1.0.1" }, "overrides": { - "lodash.template": "4.5.0" + "lodash.template": "4.18.0" }, "optionalDependencies": { "@tryghost/html-to-mobiledoc": "3.3.1", diff --git a/package.json b/package.json index 54f46de93f4..56eed0af3eb 100644 --- a/package.json +++ b/package.json @@ -76,7 +76,7 @@ "eslint-plugin-ghost>@typescript-eslint/utils": "8.49.0", "ember-svg-jar>cheerio": "1.0.0-rc.12", "juice>cheerio": "0.22.0", - "lodash.template": "4.5.0", + "lodash.template": "4.18.0", "@babel/runtime@<7.26.10": "^7.26.10", "@tootallnate/once@<3.0.1": "^3.0.1", "ansi-html@<0.0.8": "^0.0.8", diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index 1e2e0ee3c68..23fe4ec5ef4 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -35,7 +35,7 @@ overrides: eslint-plugin-ghost>@typescript-eslint/utils: 8.49.0 ember-svg-jar>cheerio: 1.0.0-rc.12 juice>cheerio: 0.22.0 - lodash.template: 4.5.0 + lodash.template: 4.18.0 '@babel/runtime@<7.26.10': ^7.26.10 '@tootallnate/once@<3.0.1': ^3.0.1 ansi-html@<0.0.8: ^0.0.8 @@ -16598,9 +16598,9 @@ packages: lodash.sortby@4.7.0: resolution: {integrity: sha512-HDWXG8isMntAyRF5vZ7xKuEvOhT4AhlRt/3czTSjvGUxjYCBVRQY48ViDHyfYz9VIoBkW4TMGQNapx+l3RUwdA==} - lodash.template@4.5.0: - resolution: {integrity: sha512-84vYFxIkmidUiFxidA/KjjH9pAycqW+h980j7Fuz5qxRtO9pgB7MDFTdys1N7A5mcucRiDyEq4fusljItR1T/A==} - deprecated: This package is deprecated. Use https://socket.dev/npm/package/eta instead. + lodash.template@4.18.0: + resolution: {integrity: sha512-VbCU2mYTHF/JUjasKG50ozrbli//eixCFmKBiAfvmz0cGt7iywc087M7zxflSoEQFS0Xtv0RqpE8ko8BXv3TOQ==} + deprecated: Bad release. Please use lodash.template@4.5.0 instead. lodash.templatesettings@4.2.0: resolution: {integrity: sha512-stgLz+i3Aa9mZgnjr/O+v9ruKZsPsndy7qPZOchbqk2cnTU1ZaldKK+v7m54WoKIyxiuMZTKT2H81F8BeAc3ZQ==} @@ -19055,6 +19055,7 @@ packages: engines: {node: '>=0.6.0', teleport: '>=0.2.0'} deprecated: |- You or someone you depend on is using Q, the JavaScript Promise library that gave JavaScript developers strong feelings about promises. They can almost certainly migrate to the native JavaScript promise now. Thank you literally everyone for joining me in this bet against the odds. Be excellent to each other. + (For a CapTP with native promises, see @endo/eventual-send and @endo/captp) qs@6.14.2: @@ -30208,7 +30209,7 @@ snapshots: '@tryghost/tpl@0.1.40': dependencies: - lodash.template: 4.5.0 + lodash.template: 4.18.0 '@tryghost/tpl@2.1.0': {} @@ -33405,7 +33406,7 @@ snapshots: dependencies: broccoli-plugin: 1.3.1 fs-tree-diff: 0.5.9 - lodash.template: 4.5.0 + lodash.template: 4.18.0 rimraf: 2.7.1 walk-sync: 0.3.4 transitivePeerDependencies: @@ -36016,7 +36017,7 @@ snapshots: js-yaml: 3.14.2 json-stable-stringify: 1.3.0 leek: 0.0.24 - lodash.template: 4.5.0 + lodash.template: 4.18.0 markdown-it: 12.3.2 markdown-it-terminal: 0.2.1 minimatch: 3.1.5 @@ -41156,7 +41157,7 @@ snapshots: lodash.sortby@4.7.0: {} - lodash.template@4.5.0: + lodash.template@4.18.0: dependencies: lodash._reinterpolate: 3.0.0 lodash.templatesettings: 4.2.0 @@ -45515,7 +45516,7 @@ snapshots: dependencies: jsesc: 0.3.0 lodash.foreach: 4.5.0 - lodash.template: 4.5.0 + lodash.template: 4.18.0 source-map: 0.1.43 spawn-args@0.2.0: {}