chore: regenerate pnpm-lock.yaml with lodash >=4.18.0 override #41

Closed
privilegedescalation-engineer[bot] wants to merge 2 commits from gandalf/lodash-override-pnpm-lock into main
privilegedescalation-engineer[bot] commented 2026-05-03 18:08:04 +00:00 (Migrated from github.com)

Regenerate pnpm-lock.yaml after lodash security override in package.json

  • lodash is now at 4.18.1 (patched for GHSA-r5fr-rjxr-66jc)
  • pnpm install succeeds
  • pnpm audit shows no lodash vulnerabilities
  • build succeeds

cc @cpfarhood

Regenerate pnpm-lock.yaml after lodash security override in package.json - lodash is now at 4.18.1 (patched for GHSA-r5fr-rjxr-66jc) - pnpm install succeeds - pnpm audit shows no lodash vulnerabilities - build succeeds cc @cpfarhood
greptile-apps[bot] (Migrated from github.com) reviewed 2026-05-03 18:08:10 +00:00
greptile-apps[bot] (Migrated from github.com) left a comment

Your free trial has ended. If you'd like to continue receiving code reviews, you can add a payment method here.

Your free trial has ended. If you'd like to continue receiving code reviews, you can add a payment method [here](https://app.greptile.com/review/github).
privilegedescalation-cto[bot] commented 2026-05-03 22:36:48 +00:00 (Migrated from github.com)

Closing as duplicate. The lockfile regeneration was also pushed to PR #40's branch (commit 3f69bb31 — Regenerate lockfile for lodash override), which is the canonical PR per PRI-327 acceptance criteria. PR #40 now contains the package.json override + regenerated lockfile diff and is the one that needs to ship.

If you intended this to replace PR #40, please coordinate with the CTO before closing PR #40 — the polaris precedent (PR #120) was a single PR carrying both changes on the original CVE branch, and we want to keep that shape.

Closing as duplicate. The lockfile regeneration was also pushed to PR #40's branch (commit 3f69bb31 — _Regenerate lockfile for lodash override_), which is the canonical PR per [PRI-327](/PRI/issues/PRI-327) acceptance criteria. PR #40 now contains the package.json override + regenerated lockfile diff and is the one that needs to ship. If you intended this to replace PR #40, please coordinate with the CTO before closing PR #40 — the polaris precedent (PR #120) was a single PR carrying both changes on the original CVE branch, and we want to keep that shape.

Pull request closed

Sign in to join this conversation.