From 6ff205e8308a0dbff3bb24f10e3f6005bc0e8663 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Thu, 22 Jan 2026 13:35:20 +0000 Subject: [PATCH] fix: package.json & pnpm-lock.yaml to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-LODASH-15053838 --- package.json | 2 +- pnpm-lock.yaml | 26 +++++++++++++------------- 2 files changed, 14 insertions(+), 14 deletions(-) diff --git a/package.json b/package.json index 62c37b4..31bd568 100644 --- a/package.json +++ b/package.json @@ -36,7 +36,7 @@ "@types/lodash": "^4.17.20", "clsx": "^2.1.1", "dotenv": "^17.2.1", - "lodash": "^4.17.21", + "lodash": "^4.17.23", "lucide-react": "^0.536.0", "mongodb": "^6.18.0", "next": "15.5.0", diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index 3e41ce7..2cdd44b 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -69,8 +69,8 @@ importers: specifier: ^17.2.1 version: 17.2.3 lodash: - specifier: ^4.17.21 - version: 4.17.21 + specifier: ^4.17.23 + version: 4.17.23 lucide-react: specifier: ^0.536.0 version: 0.536.0(react@19.2.0) @@ -1956,8 +1956,8 @@ packages: lodash.merge@4.6.2: resolution: {integrity: sha512-0KpjqXRVvrYyCsX1swR/XTK0va6VQkQM6MNo7PqW77ByjAhoARA8EfrP1N4+KlKj8YS0ZUCtRT/YUuhyYDujIQ==} - lodash@4.17.21: - resolution: {integrity: sha512-v2kDEe57lecTulaDIuNTPy3Ry4gLGJ6Z1O3vE1krgXZNrsQ+LFTGHVxVjcXPs17LhbZVGedAJv8XZ1tvj5FvSg==} + lodash@4.17.23: + resolution: {integrity: sha512-LgVTMpQtIopCi79SJeDiP0TfWi5CNEc/L/aRdTh3yIvmZXTnheWpKjSZhnvMl8iXbC1tFg9gdHHDMLoV7CnG+w==} loose-envify@1.4.0: resolution: {integrity: sha512-lyuxPGr/Wfhrlem2CL/UcnUc1zcqKAImBDzukY7Y5F/yQiNdko6+fRLevlw1HgMySw7f611UIY408EtxRSoK3Q==} @@ -2996,7 +2996,7 @@ snapshots: '@nivo/core': 0.99.0(react-dom@19.2.0(react@19.2.0))(react@19.2.0) '@nivo/theming': 0.99.0(react@19.2.0) '@react-spring/web': 10.0.3(react-dom@19.2.0(react@19.2.0))(react@19.2.0) - lodash: 4.17.21 + lodash: 4.17.23 react: 19.2.0 transitivePeerDependencies: - react-dom @@ -3047,7 +3047,7 @@ snapshots: '@types/d3-shape': 3.1.7 d3-scale: 4.0.2 d3-shape: 3.2.0 - lodash: 4.17.21 + lodash: 4.17.23 react: 19.2.0 transitivePeerDependencies: - react-dom @@ -3065,7 +3065,7 @@ snapshots: d3-scale: 4.0.2 d3-time: 1.1.0 d3-time-format: 3.0.0 - lodash: 4.17.21 + lodash: 4.17.23 react: 19.2.0 transitivePeerDependencies: - react-dom @@ -3082,7 +3082,7 @@ snapshots: d3-color: 3.1.0 d3-scale: 4.0.2 d3-scale-chromatic: 3.1.0 - lodash: 4.17.21 + lodash: 4.17.23 react: 19.2.0 transitivePeerDependencies: - react-dom @@ -3100,7 +3100,7 @@ snapshots: d3-scale-chromatic: 3.1.0 d3-shape: 3.2.0 d3-time-format: 3.0.0 - lodash: 4.17.21 + lodash: 4.17.23 react: 19.2.0 react-virtualized-auto-sizer: 1.0.26(react-dom@19.2.0(react@19.2.0))(react@19.2.0) use-debounce: 10.0.6(react@19.2.0) @@ -3116,7 +3116,7 @@ snapshots: '@nivo/tooltip': 0.99.0(react-dom@19.2.0(react@19.2.0))(react@19.2.0) d3-format: 1.4.5 d3-geo: 1.12.1 - lodash: 4.17.21 + lodash: 4.17.23 react: 19.2.0 transitivePeerDependencies: - react-dom @@ -3194,7 +3194,7 @@ snapshots: d3-scale: 4.0.2 d3-time: 1.1.0 d3-time-format: 3.0.0 - lodash: 4.17.21 + lodash: 4.17.23 '@nivo/text@0.99.0(react-dom@19.2.0(react@19.2.0))(react@19.2.0)': dependencies: @@ -3207,7 +3207,7 @@ snapshots: '@nivo/theming@0.99.0(react@19.2.0)': dependencies: - lodash: 4.17.21 + lodash: 4.17.23 react: 19.2.0 '@nivo/tooltip@0.99.0(react-dom@19.2.0(react@19.2.0))(react@19.2.0)': @@ -4741,7 +4741,7 @@ snapshots: lodash.merge@4.6.2: {} - lodash@4.17.21: {} + lodash@4.17.23: {} loose-envify@1.4.0: dependencies: