Skip to content

chore: update lodash to 4.18.1#159

Open
jcstein wants to merge 1 commit intomainfrom
jcstein/fix-lodash-vulns
Open

chore: update lodash to 4.18.1#159
jcstein wants to merge 1 commit intomainfrom
jcstein/fix-lodash-vulns

Conversation

@jcstein
Copy link
Copy Markdown
Member

@jcstein jcstein commented Apr 14, 2026

Summary

Resolves https://github.com/celestiaorg/celestia.org/security/dependabot?q=is%3Aopen+manifest%3Apackage-lock.json+package%3Alodash

  • update the locked transitive lodash dependency from 4.17.23 to 4.18.1
  • clear the open package-lock.json Dependabot alerts for lodash
  • avoid broader dependency churn by limiting the change to the lockfile entry

Verification

  • npm update lodash --package-lock-only --ignore-scripts
  • npm audit --json no longer reports a lodash vulnerability
  • npm audit --omit=dev --json no longer reports a lodash vulnerability

@jcstein jcstein requested a review from renaynay April 14, 2026 21:16
@jcstein jcstein self-assigned this Apr 14, 2026
@github-actions
Copy link
Copy Markdown

🔗 Link Checker Results

Broken Links Report

Metric Count
Total Scanned 265
✅ OK 263
🛡️ Bot Protected (403 accepted) 50
⏭️ Skipped 0
❌ Broken 2

Broken Links

525 SSL Handshake Failed

404 Not Found

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants