Skip to content

Commit 6f91180

Browse files
chargomeclaude
andauthored
fix(deps): Bump lodash to 4.17.23 (#19211)
Bump transitive lodash dependency from 4.17.21 to 4.17.23 to address CVE-2025-13465 (prototype pollution in `_.unset` and `_.omit`). Fixes https://github.com/getsentry/sentry-javascript/security/dependabot/966 Co-authored-by: Claude <noreply@anthropic.com>
1 parent 36d8f88 commit 6f91180

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

yarn.lock

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -22180,9 +22180,9 @@ lodash.uniq@^4.2.0, lodash.uniq@^4.5.0:
2218022180
integrity sha1-0CJTc662Uq3BvILklFM5qEJ1R3M=
2218122181

2218222182
lodash@^4.17.12, lodash@^4.17.14, lodash@^4.17.15, lodash@^4.17.19, lodash@^4.17.20, lodash@^4.17.21, lodash@~4.17.21:
22183-
version "4.17.21"
22184-
resolved "https://registry.yarnpkg.com/lodash/-/lodash-4.17.21.tgz#679591c564c3bffaae8454cf0b3df370c3d6911c"
22185-
integrity sha512-v2kDEe57lecTulaDIuNTPy3Ry4gLGJ6Z1O3vE1krgXZNrsQ+LFTGHVxVjcXPs17LhbZVGedAJv8XZ1tvj5FvSg==
22183+
version "4.17.23"
22184+
resolved "https://registry.yarnpkg.com/lodash/-/lodash-4.17.23.tgz#f113b0378386103be4f6893388c73d0bde7f2c5a"
22185+
integrity sha512-LgVTMpQtIopCi79SJeDiP0TfWi5CNEc/L/aRdTh3yIvmZXTnheWpKjSZhnvMl8iXbC1tFg9gdHHDMLoV7CnG+w==
2218622186

2218722187
log-symbols@^2.2.0:
2218822188
version "2.2.0"

0 commit comments

Comments
 (0)