Skip to content

chore(deps): bump lodash 4.17.21 → 4.17.23 across all packages#3390

Open
igorDykhta wants to merge 1 commit intomasterfrom
chore/combined-safe-dependency-bumps
Open

chore(deps): bump lodash 4.17.21 → 4.17.23 across all packages#3390
igorDykhta wants to merge 1 commit intomasterfrom
chore/combined-safe-dependency-bumps

Conversation

@igorDykhta
Copy link
Copy Markdown
Collaborator

Summary

What changed in lodash 4.17.23

Patch-level security fix addressing prototype pollution vulnerabilities. No functional changes.

Dependabot PRs to close after merge

Test plan

  • CI passes (yarn install, type check, lint, tests)
  • Verify no runtime regressions in demo app

Made with Cursor

Copilot AI review requested due to automatic review settings April 25, 2026 01:49
Security patch for lodash - covers all workspace packages, website, and
examples. Consolidates dependabot PRs #3283, #3284, #3285, #3286, #3287,
#3288, #3289 plus additional packages that dependabot missed (actions,
layers, table, schemas, get-started-vite).

Signed-off-by: Ihor Dykhta <dikhta.igor@gmail.com>
@igorDykhta igorDykhta force-pushed the chore/combined-safe-dependency-bumps branch from 7edd696 to 03a94b5 Compare April 25, 2026 01:51
@igorDykhta igorDykhta requested a review from lixun910 April 25, 2026 01:52
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the monorepo to use lodash 4.17.23 (security patch) by bumping version pins across package manifests and refreshing relevant Yarn lockfiles.

Changes:

  • Bump lodash from 4.17.214.17.23 in 11 package.json files across the repo.
  • Update root package.json resolutions to force lodash@4.17.23.
  • Update yarn.lock and website/yarn.lock to reflect the lodash upgrade.

Reviewed changes

Copilot reviewed 11 out of 13 changed files in this pull request and generated 1 comment.

Show a summary per file
File Description
yarn.lock Updates root lock resolution for lodash@4.17.23.
package.json Updates root resolutions.lodash to 4.17.23.
src/actions/package.json Bumps direct lodash dependency to 4.17.23.
src/components/package.json Bumps direct lodash dependency to 4.17.23.
src/deckgl-layers/package.json Bumps direct lodash dependency to 4.17.23.
src/layers/package.json Bumps direct lodash dependency to 4.17.23.
src/reducers/package.json Bumps direct lodash dependency to 4.17.23.
src/schemas/package.json Bumps direct lodash dependency to 4.17.23.
src/table/package.json Bumps direct lodash dependency to 4.17.23.
src/utils/package.json Bumps direct lodash dependency to 4.17.23.
website/package.json Bumps website direct lodash dependency to 4.17.23.
website/yarn.lock Updates website lockfile to include lodash@4.17.23.
examples/get-started-vite/package.json Bumps example app direct lodash dependency to 4.17.23.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread package.json
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants