-
-
Notifications
You must be signed in to change notification settings - Fork 9.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Security] Bump lodash from 4.17.11 to 4.17.15 #8351
Conversation
This pull request is automatically deployed with Now. Latest deployment for this branch: https://monorepo-git-fork-nminhnguyen-lodash.storybook.now.sh |
@shilman there's some build failures but I'm guessing they're unrelated? Btw the motivation for this change is I was tryna onboard Storybook to our private npm registry at work, but it leverages Snyk for vulnerability scanning and it rejected my request due to |
[Security] Bump lodash from 4.17.11 to 4.17.15
See https://www.npmjs.com/advisories/1065
Issue:
What I did
Updated to the latest published Lodash version. I could've just bumped to
^4.17.12
as per the advisory, but figured I might as well use the latest version. Although^4.17.11
does allow the installation of newer non-vulnerable versions,4.17.11
satisfies that version range and seems to causeSnyk
to produce warnings.How to test
If your answer is yes to any of these, please make sure to include it in your PR.