Skip to content

build(deps): bump lodash from 4.17.21 to 4.18.0 in /chat2db-community-client#1992

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/chat2db-community-client/lodash-4.18.0
Open

build(deps): bump lodash from 4.17.21 to 4.18.0 in /chat2db-community-client#1992
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/chat2db-community-client/lodash-4.18.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 24, 2026

Copy link
Copy Markdown

Bumps lodash from 4.17.21 to 4.18.0.

Release notes

Sourced from lodash's releases.

4.18.0

v4.18.0

Full Changelog: lodash/lodash@4.17.23...4.18.0

Security

_.unset / _.omit: Fixed prototype pollution via constructor/prototype path traversal (GHSA-f23m-r3pf-42rh, fe8d32e). Previously, array-wrapped path segments and primitive roots could bypass the existing guards, allowing deletion of properties from built-in prototypes. Now constructor and prototype are blocked unconditionally as non-terminal path keys, matching baseSet. Calls that previously returned true and deleted the property now return false and leave the target untouched.

_.template: Fixed code injection via imports keys (GHSA-r5fr-rjxr-66jc, CVE-2026-4800, 879aaa9). Fixes an incomplete patch for CVE-2021-23337. The variable option was validated against reForbiddenIdentifierChars but importsKeys was left unguarded, allowing code injection via the same Function() constructor sink. imports keys containing forbidden identifier characters now throw "Invalid imports option passed into _.template".

Docs

  • Add security notice for _.template in threat model and API docs (#6099)
  • Document lower > upper behavior in _.random (#6115)
  • Fix quotes in _.compact jsdoc (#6090)

lodash.* modular packages

Diff

We have also regenerated and published a select number of the lodash.* modular packages.

These modular packages had fallen out of sync significantly from the minor/patch updates to lodash. Specifically, we have brought the following packages up to parity w/ the latest lodash release because they have had CVEs on them in the past:

Commits
  • 59be2de release(minor): bump to 4.18.0 (#6161)
  • af63457 fix: broken tests for _.template 879aaa9
  • 1073a76 fix: linting issues
  • 879aaa9 fix: validate imports keys in _.template
  • fe8d32e fix: block prototype pollution in baseUnset via constructor/prototype traversal
  • 18ba0a3 refactor(fromPairs): use baseAssignValue for consistent assignment (#6153)
  • b819080 ci: add dist sync validation workflow (#6137)
  • 0783181 docs(random): document lower > upper case (#6115)
  • 35bb1d9 docs: add security notice for _.template in threat model and API docs (#6099)
  • 62b439f doc: fix quotes in compact jsdoc (#6090)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 24, 2026
@dependabot
dependabot Bot requested a review from openai0229 as a code owner July 24, 2026 04:19
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 24, 2026
@openai0229 openai0229 moved this to In Review in Chat2DB Community Jul 24, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/chat2db-community-client/lodash-4.18.0 branch 2 times, most recently from b7679f1 to 62ca2f4 Compare July 24, 2026 18:12
Bumps [lodash](https://github.com/lodash/lodash) from 4.17.21 to 4.18.0.
- [Release notes](https://github.com/lodash/lodash/releases)
- [Commits](lodash/lodash@4.17.21...4.18.0)

---
updated-dependencies:
- dependency-name: lodash
  dependency-version: 4.18.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): bump lodash from 4.17.21 to 4.18.0 in /chat2db-community-client build(deps): bump lodash from 4.17.21 to 4.18.0 in /chat2db-community-client Jul 25, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/chat2db-community-client/lodash-4.18.0 branch from 62ca2f4 to 92fce71 Compare July 25, 2026 15:29
@dependabot @github

dependabot Bot commented on behalf of github Jul 25, 2026

Copy link
Copy Markdown
Author

Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot recreate.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

Status: In Review

Development

Successfully merging this pull request may close these issues.

1 participant