Skip to content

Upgrade lodash to 4.17.13#10191

Merged
danez merged 1 commit into
babel:masterfrom
CYBAI:upgrade-lodash
Jul 12, 2019
Merged

Upgrade lodash to 4.17.13#10191
danez merged 1 commit into
babel:masterfrom
CYBAI:upgrade-lodash

Conversation

@CYBAI

@CYBAI CYBAI commented Jul 10, 2019

Copy link
Copy Markdown
Contributor

As @jdalton said, it's time to update lodash so that we can fix the security vulnerability reported by Snyk.

Q                       A
Fixed Issues?
Patch: Bug Fix? No
Major: Breaking Change? No
Minor: New Feature? No
Tests Added + Pass? Yes
Documentation PR Link
Any Dependency Changes? Upgrade all lodash to 4.17.13
License MIT

@babel-bot

babel-bot commented Jul 10, 2019

Copy link
Copy Markdown
Collaborator

Build successful! You can test your changes in the REPL here: https://babeljs.io/repl/build/11097/

@babel-bot

Copy link
Copy Markdown
Collaborator

Build successful! You can test your changes in the REPL here: https://babeljs.io/repl/build/11096/

Comment thread yarn.lock Outdated
Comment thread yarn.lock
integrity sha512-YuZKluhWGJwCcUu4RlZstdAxr8bFfOVHakc1mplwHkk8J+tqM1Y5yraYvIUpeX8aY7+crCwiELJq7Vl0o0LWXw==

node-fetch@^2.5.0:
node-fetch@^2.3.0, node-fetch@^2.5.0:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It seems unrelated to lodash upgrade. But I am happy to leave it as-is.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hmm, maybe it's caused by running yarn-deduplicate 🤔? If others hope this change to be removed, please let me know!

@danez
danez merged commit 42000b9 into babel:master Jul 12, 2019
@CYBAI
CYBAI deleted the upgrade-lodash branch July 12, 2019 08:33
Jyrno42 added a commit to thorgate/tg-modal that referenced this pull request Jul 16, 2019
Remove once babel/babel#10191 has been released
@lock lock Bot added the outdated A closed issue/PR that is archived due to age. Recommended to make a new issue label Oct 11, 2019
@lock lock Bot locked as resolved and limited conversation to collaborators Oct 11, 2019
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

outdated A closed issue/PR that is archived due to age. Recommended to make a new issue PR: Dependency ⬆️

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants