Skip to content

Update dependency lodash to v4.17.23 (main)#238

Open
mend-for-github-com[bot] wants to merge 1 commit into
mainfrom
whitesource-remediate/main-lodash-4.x-lockfile
Open

Update dependency lodash to v4.17.23 (main)#238
mend-for-github-com[bot] wants to merge 1 commit into
mainfrom
whitesource-remediate/main-lodash-4.x-lockfile

Conversation

@mend-for-github-com
Copy link
Copy Markdown

@mend-for-github-com mend-for-github-com Bot commented May 14, 2026

This PR contains the following updates:

Package Type Update Change
lodash (source) dependencies patch 4.17.104.17.23

By merging this PR, the issue #109 will be automatically resolved and closed:

Severity CVSS Score Vulnerability Reachability
High High 7.4 CVE-2020-8203

Unreachable

High High 7.2 CVE-2021-23337

Unreachable

Medium Medium 6.5 CVE-2019-1010266

Unreachable

Medium Medium 6.5 CVE-2026-2950

Unreachable


Release Notes

lodash/lodash (lodash)

v4.17.23

Compare Source

v4.17.21

Compare Source

v4.17.20

Compare Source

v4.17.16

Compare Source

v4.17.15

Compare Source

v4.17.14

Compare Source

v4.17.13

Compare Source

v4.17.12

Compare Source

v4.17.11

Compare Source


  • If you want to rebase/retry this PR, check this box

@mend-for-github-com mend-for-github-com Bot added the security fix Security fix generated by Mend label May 14, 2026
@mend-for-github-com mend-for-github-com Bot changed the title Update dependency lodash to v4.17.11 (main) Update dependency lodash to v4.17.11 (main) - autoclosed May 15, 2026
@mend-for-github-com mend-for-github-com Bot deleted the whitesource-remediate/main-lodash-4.x-lockfile branch May 15, 2026 13:29
@mend-for-github-com mend-for-github-com Bot changed the title Update dependency lodash to v4.17.11 (main) - autoclosed Update dependency lodash to v4.17.11 (main) May 21, 2026
@mend-for-github-com mend-for-github-com Bot reopened this May 21, 2026
@mend-for-github-com mend-for-github-com Bot force-pushed the whitesource-remediate/main-lodash-4.x-lockfile branch 2 times, most recently from 474674e to 0338eee Compare May 21, 2026 01:21
@mend-for-github-com mend-for-github-com Bot force-pushed the whitesource-remediate/main-lodash-4.x-lockfile branch from 0338eee to baae656 Compare May 23, 2026 00:15
@mend-for-github-com mend-for-github-com Bot changed the title Update dependency lodash to v4.17.11 (main) Update dependency lodash to v4.17.23 (main) May 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants