Skip to content

Bump lodash and lodash-es from 4.17.23 to 4.18.1 in /ui/form#1077

Merged
kaidaguerre merged 1 commit into
developfrom
bump-lodash-4.18.1
Jun 15, 2026
Merged

Bump lodash and lodash-es from 4.17.23 to 4.18.1 in /ui/form#1077
kaidaguerre merged 1 commit into
developfrom
bump-lodash-4.18.1

Conversation

@kaidaguerre

Copy link
Copy Markdown
Contributor

Resolves CVE-2026-4800 (HIGH). Both lodash and lodash-es are pinned via the resolutions block in ui/form/package.json; 4.17.23 is within the vulnerable range (<= 4.17.23), fixed in 4.18.1.

Dependabot did not raise a PR for these (they sit in resolutions, not as direct deps), so this is the manual override. Minor bump, no API changes; tsc + vite build pass locally. Matches the equivalent powerpipe bump (lodash 4.17.23→4.18.1).

Resolves CVE-2026-4800. Both are pinned via the resolutions block; 4.17.23
is within the vulnerable range (<= 4.17.23), fixed in 4.18.1. Minor bump,
no API changes; tsc + vite build pass.
@kaidaguerre kaidaguerre merged commit bbb411e into develop Jun 15, 2026
8 of 9 checks passed
@kaidaguerre kaidaguerre deleted the bump-lodash-4.18.1 branch June 15, 2026 16:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants