From ef4f1b0037a0ab3d791ce7549ed837cf3124d73d Mon Sep 17 00:00:00 2001 From: Claude Date: Thu, 23 Apr 2026 11:27:00 +0000 Subject: [PATCH] chore(security): patch 4 Dependabot alerts Bump lodash and lodash-es resolutions from ^4.17.23 to ^4.18.0 to address GHSA prototype-pollution (medium) and code-injection via _.template (high) in both packages. Both now resolve to 4.18.1. Also remove two redundant resolutions whose natural resolution now satisfies the original pin: - js-yaml: natural tree already resolves to 4.1.1 - ajv: natural tree already resolves to 8.18.0 Addresses Dependabot alerts #65, #66, #67, #68. --- package.json | 6 ++---- yarn.lock | 20 ++++++++++---------- 2 files changed, 12 insertions(+), 14 deletions(-) diff --git a/package.json b/package.json index 1c1701eb8..b56c1c55c 100644 --- a/package.json +++ b/package.json @@ -23,9 +23,7 @@ }, "resolutions": { "semantic-release-slack-bot/**/micromatch": "^4.0.8", - "lodash": "^4.17.23", - "lodash-es": "^4.17.23", - "js-yaml": "^4.1.1", - "ajv": "^8.18.0" + "lodash": "^4.18.0", + "lodash-es": "^4.18.0" } } diff --git a/yarn.lock b/yarn.lock index 6d9c89b16..70941785b 100644 --- a/yarn.lock +++ b/yarn.lock @@ -856,7 +856,7 @@ aggregate-error@^5.0.0: clean-stack "^5.2.0" indent-string "^5.0.0" -ajv@^8.11.0, ajv@^8.18.0: +ajv@^8.11.0: version "8.18.0" resolved "https://registry.yarnpkg.com/ajv/-/ajv-8.18.0.tgz#8864186b6738d003eb3a933172bb3833e10cefbc" integrity sha512-PlXPeEWMXMZ7sPYOHqmDyCJzcfNrUr3fGNKtezX14ykXOEIvyK81d+qydx89KY5O71FKMPaQ2vBfBFI5NHR63A== @@ -2060,7 +2060,7 @@ js-tokens@^4.0.0: resolved "https://registry.yarnpkg.com/js-tokens/-/js-tokens-4.0.0.tgz#19203fb59991df98e3a287050d4647cdeaf32499" integrity sha512-RdJUflcE3cUzKiMqQgsCu06FPu9UdIJO0beYbPhHN4k6apgJtifcoCtT9bcxOpYBtpD2kCM6Sbzg4CausW/PKQ== -js-yaml@^4.1.0, js-yaml@^4.1.1: +js-yaml@^4.1.0: version "4.1.1" resolved "https://registry.yarnpkg.com/js-yaml/-/js-yaml-4.1.1.tgz#854c292467705b699476e1a2decc0c8a3458806b" integrity sha512-qQKT4zQxXl8lLwBtHMWwaTcGfFOZviOJet3Oy/xmGk2gZH677CJM9EvtfdSkgWcATZhj/55JZ0rmy3myCT5lsA== @@ -2268,10 +2268,10 @@ locate-path@^6.0.0: dependencies: p-locate "^5.0.0" -lodash-es@^4.17.21, lodash-es@^4.17.23: - version "4.17.23" - resolved "https://registry.yarnpkg.com/lodash-es/-/lodash-es-4.17.23.tgz#58c4360fd1b5d33afc6c0bbd3d1149349b1138e0" - integrity sha512-kVI48u3PZr38HdYz98UmfPnXl2DXrpdctLrFLCd3kOx1xUkOmpFPx7gCWWM5MPkL/fD8zb+Ph0QzjGFs4+hHWg== +lodash-es@^4.17.21, lodash-es@^4.18.0: + version "4.18.1" + resolved "https://registry.yarnpkg.com/lodash-es/-/lodash-es-4.18.1.tgz#b962eeb80d9d983a900bf342961fb7418ca10b1d" + integrity sha512-J8xewKD/Gk22OZbhpOVSwcs60zhd95ESDwezOFuA3/099925PdHJ7OFHNTGtajL3AlZkykD32HykiMo+BIBI8A== lodash.camelcase@^4.3.0: version "4.3.0" @@ -2343,10 +2343,10 @@ lodash.upperfirst@^4.3.1: resolved "https://registry.yarnpkg.com/lodash.upperfirst/-/lodash.upperfirst-4.3.1.tgz#1365edf431480481ef0d1c68957a5ed99d49f7ce" integrity sha512-sReKOYJIJf74dhJONhU4e0/shzi1trVbSWDOhKYE5XV2O+H7Sb2Dihwuc7xWxVl+DgFPyTqIN3zMfT9cq5iWDg== -lodash@^4.17.15, lodash@^4.17.23, lodash@^4.17.4: - version "4.17.23" - resolved "https://registry.yarnpkg.com/lodash/-/lodash-4.17.23.tgz#f113b0378386103be4f6893388c73d0bde7f2c5a" - integrity sha512-LgVTMpQtIopCi79SJeDiP0TfWi5CNEc/L/aRdTh3yIvmZXTnheWpKjSZhnvMl8iXbC1tFg9gdHHDMLoV7CnG+w== +lodash@^4.17.15, lodash@^4.17.4, lodash@^4.18.0: + version "4.18.1" + resolved "https://registry.yarnpkg.com/lodash/-/lodash-4.18.1.tgz#ff2b66c1f6326d59513de2407bf881439812771c" + integrity sha512-dMInicTPVE8d1e5otfwmmjlxkZoUpiVLwyeTdUsi/Caj/gfzzblBcCE5sRHV/AsjuCmxWrte2TNGSYuCeCq+0Q== longest-streak@^2.0.0: version "2.0.4"