Skip to content
This repository has been archived by the owner on Nov 17, 2023. It is now read-only.

fix(deps): update all lodash variants to 4.17.14 #2570

Merged
merged 1 commit into from
Jul 14, 2019

Conversation

mrfelton
Copy link
Member

@mrfelton mrfelton commented Jul 11, 2019

Description:

Update all lodash variants to 4.17.14. This is meant as a temporary override until all of our dependencies get around to upgrading.

Motivation and Context:

Update lodash dependencies to avoid CVEs found in the 'lodash' package.

How Has This Been Tested?

Manually

Types of changes:

Security upgrade

Checklist:

  • My code follows the code style of this project.
  • I have reviewed and updated the documentation accordingly.
  • I have read the CONTRIBUTING document.
  • I have added tests to cover my changes where needed.
  • All new and existing tests passed.
  • My commits have been squashed into a concise set of changes.

@mrfelton mrfelton added scope: security issues that are security related dependencies Pull requests that update a dependency file labels Jul 11, 2019
@mrfelton mrfelton added this to the v0.5.1-beta milestone Jul 11, 2019
@mrfelton mrfelton requested a review from korhaliv July 11, 2019 20:00
@mrfelton mrfelton self-assigned this Jul 11, 2019
Update lodash dependencies to avoid CVEs found in the 'lodash' package.
@mrfelton mrfelton changed the title fix(deps): update all lodash variants to 4.17.13 fix(deps): update all lodash variants to 4.17.14 Jul 11, 2019
@coveralls
Copy link

coveralls commented Jul 11, 2019

Coverage Status

Coverage remained the same at 20.132% when pulling ed65548 on mrfelton:fix/lodash-update into ba579f6 on LN-Zap:master.

Copy link
Member

@JimmyMow JimmyMow left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Concept ACK

Copy link
Member

@korhaliv korhaliv left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Tested ACK ed65548

@mrfelton mrfelton merged commit 51c75e2 into LN-Zap:master Jul 14, 2019
@mrfelton mrfelton deleted the fix/lodash-update branch July 14, 2019 19:03
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
dependencies Pull requests that update a dependency file scope: security issues that are security related
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants