fix(deps): vuln major upgrades — 5 packages (major: 3 · unstable: 1 · minor: 1) #28
Conversation
Release Noteslodash (4.17.21 → 4.18.1) — GitHub Release4.18.1BugsFixes a These defects were related to how lodash distributions are built from the main branch using https://github.com/lodash-archive/lodash-cli. When internal dependencies change inside lodash functions, equivalent updates need to be made to a mapping in the lodash-cli. (hey, it was ahead of its time once upon a time!). We know this, but we missed it in the last release. It's the kind of thing that passes in CI, but fails bc the build is not the same thing you tested. There is no diff on main for this, but you can see the diffs for each of the npm packages on their respective branches:
4.18.0v4.18.0Full Changelog: lodash/lodash@4.17.23...4.18.0 Security
Docs
|
|
Hey, sorry for the noise. This was caused by a bug in our automated dependency update system that incorrectly included upstream changelog content in PR comments, triggering notifications to external contributors. The feature flag has been turned off and we're working on a fix. Sorry about that again. |
Summary: High-severity security update — 5 packages upgraded (MAJOR changes included)
Manifests changed:
.(pnpm)✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.
Updates
Packages marked with "-" are updated due to dependency constraints.
Warning
Major Version Upgrade
This update includes major version changes that may contain breaking changes. Please:
Security Details
🚨 Critical & High Severity (1 fixed)
_.templateimports key namesℹ️ Other Vulnerabilities (3)
_.unsetand_.omitfunctions_.unsetand_.omitReview Checklist
Extra review is recommended for this update:
Update Mode: Vulnerability Remediation (High)
🤖 Generated by DataDog Automated Dependency Management System