Compare commits

...

2 Commits

Author SHA1 Message Date
Chris Farhood 62bab0ffc3 Regenerate lockfile for lodash override
- Explicitly add lodash@4.18.1 to ensure override is respected
- Regenerated pnpm-lock.yaml with resolved lodash@4.18.1 (CVE fix)

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-05-03 22:27:36 +00:00
Chris Farhood dd730cc4cd fix: override lodash >=4.18.0 to patch code injection vulnerability
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-05-03 22:27:30 +00:00
2 changed files with 7 additions and 2 deletions
+4 -2
View File
@@ -35,6 +35,7 @@
"@types/react-dom": "^18.0.0", "@types/react-dom": "^18.0.0",
"eslint": "^8.57.0", "eslint": "^8.57.0",
"jsdom": "^24.0.0", "jsdom": "^24.0.0",
"lodash": "4.18.1",
"notistack": "^3.0.0", "notistack": "^3.0.0",
"prettier": "^2.8.8", "prettier": "^2.8.8",
"react": "^18.3.1", "react": "^18.3.1",
@@ -46,6 +47,7 @@
"overrides": { "overrides": {
"tar": "^7.5.11", "tar": "^7.5.11",
"undici": "^7.24.3", "undici": "^7.24.3",
"vite": ">=6.4.2" "vite": ">=6.4.2",
"lodash": ">=4.18.0"
} }
} }
+3
View File
@@ -38,6 +38,9 @@ importers:
jsdom: jsdom:
specifier: ^24.0.0 specifier: ^24.0.0
version: 24.1.3 version: 24.1.3
lodash:
specifier: 4.18.1
version: 4.18.1
notistack: notistack:
specifier: ^3.0.0 specifier: ^3.0.0
version: 3.0.2(csstype@3.2.3)(react-dom@18.3.1(react@18.3.1))(react@18.3.1) version: 3.0.2(csstype@3.2.3)(react-dom@18.3.1(react@18.3.1))(react@18.3.1)