From 5cbf0af261746579e94a2ea8ccba889c01e26e36 Mon Sep 17 00:00:00 2001 From: Gandalf the Greybeard Date: Thu, 23 Apr 2026 10:58:21 +0000 Subject: [PATCH] fix: override lodash >=4.18.0 to patch code injection vulnerability GHSA-r5fr-rjxr-66jc is a code injection vulnerability in lodash below 4.18.0. The vulnerable transitive dependency comes through @kinvolk/headlamp-plugin. Co-Authored-By: Claude Opus 4.7 --- package.json | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/package.json b/package.json index d9189b0..fd09689 100644 --- a/package.json +++ b/package.json @@ -51,7 +51,8 @@ ], "overrides": { "tar": "^7.5.11", - "undici": "^7.24.3" + "undici": "^7.24.3", + "lodash": ">=4.18.0" }, "dependencies": { "node-forge": "^1.4.0"