[Aikido] Fix security issue in lodash via minor version upgrade from 4.17.21 to 4.18.1 in examples - #97
Open
aikido-autofix[bot] wants to merge 1 commit into
Conversation
Package lock diff |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Upgrade lodash to fix critical remote code execution vulnerability in _.template via options.imports injection and medium-severity prototype pollution bypasses in _.unset and _.omit functions.
✅ Code not affected by breaking changes.
✅ No breaking changes affect this codebase. The codebase does not use
_.unset,_.omit, or_.templatemethods from lodash. While lodash is listed as a dependency in package files, searches across all JavaScript/TypeScript source files found no imports or usage of the affected methods.All breaking changes by upgrading lodash from version 4.17.21 to 4.18.1 (CHANGELOG)
_.unset/_.omitnow blockconstructorandprototypeas non-terminal path keys unconditionally. Calls that previously returnedtrueand deleted the property now returnfalseand leave the target untouched._.templatenow throws"Invalid imports option passed into _.template"whenimportskeys contain forbidden identifier characters, which were previously allowed.✅ 3 CVEs resolved by this upgrade, including 1 critical 🚨 CVE
This PR will resolve the following CVEs:
🤖 Remediation details
Fix CVE-2026-4800, CVE-2025-13465, and CVE-2026-2950 in
lodashandlodash.template(examples/with-serverless)Short summary
This PR remediates three CVEs affecting two distinct packages —
lodashandlodash.template— in theexamples/with-serverlessproject. Both packages were transitive dependencies whose lockfile-resolved versions were below the patched thresholds. Selector-patternoverrideswere added toexamples/with-serverless/package.jsonand the lockfile (examples/with-serverless/package-lock.json) was refreshed vianpm install --package-lock-only.lodash
lodashwas resolved to4.17.21in the lockfile, pulled in transitively by twelve packages (includinggatsby,gatsby-cli,gatsby-plugin-offline,inquirer, and others), all declaring it as^4.17.21. That range permits4.18.1, butnpm update lodash --package-lock-onlyleft the lockfile unchanged — safe-chain suppressed the newer releases during resolution. Because no direct dependency declaredlodashand a bare global override was undesirable, a selector override"lodash@<4.18.1": "4.18.1"was added topackage.jsonto target only sub-patched instances, bringing all twelve dependents to4.18.1.lodash.template
lodash.templateis a separate standalone npm package (not part of thelodashmonolith) and was resolved to4.5.0, pulled in byworkbox-build@4.3.1(itself a dependency ofgatsby-plugin-offline@6.15.0) via the declared range^4.4.0. That range already permits4.18.0, but safe-chain again preventednpm updatefrom advancing the resolution. A selector override"lodash.template@<4.18.0": "4.18.0"was added alongside thelodashoverride, and the lockfile was refreshed to resolvelodash.templateto4.18.0.Version changes
lodash4.17.214.18.1npm updatelodash.template4.5.04.18.0npm update