Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency lodash to v4.17.21 [SECURITY] #12

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link

@renovate renovate bot commented Jul 13, 2019

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
lodash (source) 4.17.10 -> 4.17.21 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2021-23337

lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.

CVE-2020-8203

Versions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The function zipObjectDeep allows a malicious user to modify the prototype of Object if the property identifiers are user-supplied. Being affected by this issue requires zipping objects based on user-provided property arrays.

This vulnerability causes the addition or modification of an existing property that will exist on all objects and may lead to Denial of Service or Code Execution under specific circumstances.


Release Notes

lodash/lodash

v4.17.21

Compare Source

v4.17.20

Compare Source

v4.17.16

Compare Source

v4.17.15

Compare Source

v4.17.14

Compare Source

v4.17.13

Compare Source

v4.17.12

Compare Source

v4.17.11

Compare Source


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch from 9c87d91 to 1c6fd75 Compare August 10, 2019 08:56
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch from 1c6fd75 to 63b5da9 Compare August 18, 2019 09:01
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch 2 times, most recently from 37c1fa6 to 1c9859a Compare September 7, 2019 15:57
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch from 1c9859a to 1e06ed5 Compare October 5, 2019 10:53
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch from 1e06ed5 to 56a8700 Compare November 11, 2019 00:02
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch from 56a8700 to 974ebe9 Compare November 21, 2019 11:50
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch from 974ebe9 to 805eda3 Compare December 15, 2019 01:52
@renovate renovate bot changed the title Update dependency lodash to v4.17.13 [SECURITY] Update dependency lodash to v4.17.12 [SECURITY] Dec 15, 2019
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch from 805eda3 to 72f49c6 Compare December 21, 2019 23:59
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch from 72f49c6 to c59cadd Compare December 30, 2019 13:57
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch from c59cadd to 7a9e34f Compare January 18, 2020 19:22
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch from 7a9e34f to 34d39fb Compare February 9, 2020 02:00
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch from 34d39fb to 9f3d869 Compare February 22, 2020 07:59
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch from 9f3d869 to 33483be Compare March 15, 2020 06:01
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch from 33483be to f489dba Compare April 29, 2020 09:00
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch from f489dba to 0b44e95 Compare May 7, 2020 16:54
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch from 0b44e95 to 5aa1227 Compare May 15, 2020 17:53
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch from 5aa1227 to 0a0841e Compare July 1, 2020 15:06
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch 11 times, most recently from 442a03a to f3a8896 Compare July 11, 2020 08:37
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch 12 times, most recently from 3ef85cb to 0db543d Compare July 12, 2020 06:14
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch from 0db543d to 38d5d68 Compare August 26, 2020 02:02
@renovate renovate bot changed the title Update dependency lodash to v4.17.12 [SECURITY] Update dependency lodash to v4.17.19 [SECURITY] Aug 26, 2020
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch from 38d5d68 to f284864 Compare October 25, 2020 23:56
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch from f284864 to dfc79b3 Compare November 27, 2020 01:58
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch from dfc79b3 to 2aab579 Compare December 9, 2020 00:02
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch 2 times, most recently from e4814dd to b560934 Compare January 9, 2021 14:00
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch from b560934 to b294c26 Compare January 22, 2021 13:01
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch 3 times, most recently from 4afb1e1 to 04f025b Compare February 10, 2021 08:56
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch 2 times, most recently from da6f4c0 to 23aec4b Compare February 11, 2021 14:16
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch from 23aec4b to acc3753 Compare April 26, 2021 14:39
@renovate renovate bot force-pushed the renovate/npm-lodash-vulnerability branch from acc3753 to 2cbdf5d Compare May 9, 2021 20:27
@renovate renovate bot changed the title Update dependency lodash to v4.17.19 [SECURITY] Update dependency lodash to v4.17.21 [SECURITY] May 9, 2021
@renovate
Copy link
Author

renovate bot commented Mar 25, 2023

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant