Skip to content

chore(deps-dev): bump lodash from 4.17.23 to 4.18.1 in /templates - #11061

Merged
github-actions[bot] merged 2 commits into
mainfrom
dependabot/npm_and_yarn/templates/lodash-4.18.1
Aug 11, 2026
Merged

github-actions[bot] merged 2 commits into
mainfrom
dependabot/npm_and_yarn/templates/lodash-4.18.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Apr 10, 2026 •

Copy link
Copy Markdown
Contributor

Bumps lodash from 4.17.23 to 4.18.1.

Release notes

Sourced from lodash's releases.

4.18.1

Bugs

Fixes a ReferenceError issue in lodash lodash-es lodash-amd and lodash.template when using the template and fromPairs functions from the modular builds. See lodash/lodash#6167

These defects were related to how lodash distributions are built from the main branch using https://github.com/lodash-archive/lodash-cli. When internal dependencies change inside lodash functions, equivalent updates need to be made to a mapping in the lodash-cli. (hey, it was ahead of its time once upon a time!). We know this, but we missed it in the last release. It's the kind of thing that passes in CI, but fails bc the build is not the same thing you tested.

There is no diff on main for this, but you can see the diffs for each of the npm packages on their respective branches:

4.18.0

v4.18.0

Full Changelog: lodash/lodash@4.17.23...4.18.0

Security

_.unset / _.omit: Fixed prototype pollution via constructor/prototype path traversal (GHSA-f23m-r3pf-42rh, fe8d32e). Previously, array-wrapped path segments and primitive roots could bypass the existing guards, allowing deletion of properties from built-in prototypes. Now constructor and prototype are blocked unconditionally as non-terminal path keys, matching baseSet. Calls that previously returned true and deleted the property now return false and leave the target untouched.

_.template: Fixed code injection via imports keys (GHSA-r5fr-rjxr-66jc, CVE-2026-4800, 879aaa9). Fixes an incomplete patch for CVE-2021-23337. The variable option was validated against reForbiddenIdentifierChars but importsKeys was left unguarded, allowing code injection via the same Function() constructor sink. imports keys containing forbidden identifier characters now throw "Invalid imports option passed into _.template".

Docs

  • Add security notice for _.template in threat model and API docs (#6099)
  • Document lower > upper behavior in _.random (#6115)
  • Fix quotes in _.compact jsdoc (#6090)

lodash.* modular packages

Diff

We have also regenerated and published a select number of the lodash.* modular packages.

These modular packages had fallen out of sync significantly from the minor/patch updates to lodash. Specifically, we have brought the following packages up to parity w/ the latest lodash release because they have had CVEs on them in the past:

Commits
  • cb0b9b9 release(patch): bump main to 4.18.1 (#6177)
  • 75535f5 chore: prune stale advisory refs (#6170)
  • 62e91bc docs: remove n_ Node.js < 6 REPL note from README (#6165)
  • 59be2de release(minor): bump to 4.18.0 (#6161)
  • af63457 fix: broken tests for _.template 879aaa9
  • 1073a76 fix: linting issues
  • 879aaa9 fix: validate imports keys in _.template
  • fe8d32e fix: block prototype pollution in baseUnset via constructor/prototype traversal
  • 18ba0a3 refactor(fromPairs): use baseAssignValue for consistent assignment (#6153)
  • b819080 ci: add dist sync validation workflow (#6137)
  • Additional commits viewable in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [lodash](https://github.com/lodash/lodash) from 4.17.23 to 4.18.1.
- [Release notes](https://github.com/lodash/lodash/releases)
- [Commits](lodash/lodash@4.17.23...4.18.1)

---
updated-dependencies:
- dependency-name: lodash
  dependency-version: 4.18.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Apr 10, 2026
@github-actions
github-actions Bot enabled auto-merge (squash) April 10, 2026 03:25
@github-actions
github-actions Bot merged commit 8e4ac69 into main Aug 11, 2026
8 checks passed
@github-actions
github-actions Bot deleted the dependabot/npm_and_yarn/templates/lodash-4.18.1 branch August 11, 2026 04:53
Benziza pushed a commit to Benziza/queryguard-dotnet that referenced this pull request Sep 21, 2026
Updated [docfx](https://github.com/dotnet/docfx) from 2.78.5 to 2.80.1.

<details>
<summary>Release notes</summary>

_Sourced from [docfx's
releases](https://github.com/dotnet/docfx/releases)._

## 2.80.1

<!-- Release notes generated using configuration in .github/release.yml
at main -->

## What's Changed
### 💪 Other Changes
* fix: preserve thematic breaks in overwrite Markdown by @​vicancy in
dotnet/docfx#11142
* fix: XML comment parse logics for block element that is adjacent to
markdown content by @​filzrev in
dotnet/docfx#10966
* chore: Update Roslyn and Microsoft.Build package dependencies by
@​filzrev in dotnet/docfx#11124
* fix: preserve indentation around XML comment code blocks by @​vicancy
in dotnet/docfx#11143
* fix: stop metadata generation when restore fails by @​vicancy in
dotnet/docfx#11146
* fix: clarify empty .NET API diagnostics by @​vicancy in
dotnet/docfx#11145
* fix: share tool templates across target frameworks by @​vicancy in
dotnet/docfx#11144
* fix: honor TOC metadata while preserving file metadata overrides by
@​vicancy in dotnet/docfx#11140
* fix(deps): update esbuild to 0.28.1 and tsx to 4.22.4 by
@​dependabot[bot] in dotnet/docfx#11077
* feat(pdf): allow footer and header on cover and toc by @​sergimos in
dotnet/docfx#10958
* chore(deps): bump actions/setup-dotnet from 5 to 6 by
@​dependabot[bot] in dotnet/docfx#11116
* chore(deps): bump actions/checkout from 6 to 7 by @​dependabot[bot] in
dotnet/docfx#11115
* Bump Markdig from 1.1.0 to 1.1.1 by @​dependabot[bot] in
dotnet/docfx#11024
* deps: Update JsonSchema.Net dependency to 8.0.5 by @​filzrev in
dotnet/docfx#10964

## New Contributors
* @​sergimos made their first contribution in
dotnet/docfx#10958

**Full Changelog**:
dotnet/docfx@v2.78.6...v2.80.1

## 2.78.6

<!-- Release notes generated using configuration in .github/release.yml
at main -->

## What's Changed
### 💪 Other Changes
* chore(deps): bump dependabot/fetch-metadata from 2.3.0 to 2.5.0 by
@​dependabot[bot] in dotnet/docfx#10956
* chore(deps): bump paulhatch/semantic-version from 5.4.0 to 6.0.1 by
@​dependabot[bot] in dotnet/docfx#10978
* chore(deps-dev): bump minimatch from 3.1.2 to 3.1.5 in /templates by
@​dependabot[bot] in dotnet/docfx#11016
* Bump Jint from 4.6.0 to 4.6.1 by @​dependabot[bot] in
dotnet/docfx#11018
* chore(deps): bump actions/upload-artifact from 6 to 7 by
@​dependabot[bot] in dotnet/docfx#11015
* chore(deps): bump actions/download-artifact from 7 to 8 by
@​dependabot[bot] in dotnet/docfx#11014
* Bump Markdig from 1.0.0 to 1.1.0 by @​dependabot[bot] in
dotnet/docfx#11019
* chore: remove unnecessary using to fix the Lint check by @​lahma in
dotnet/docfx#11085
* Make xref archive download test hermetic by @​vicancy in
dotnet/docfx#11092
* fix: treat different ports as external links by @​vicancy in
dotnet/docfx#11091
* chore: cleanup YamlSerializationTest.cs by @​filzrev in
dotnet/docfx#10974
* chore(deps-dev): bump follow-redirects from 1.15.11 to 1.16.0 in
/templates by @​dependabot[bot] in
dotnet/docfx#11062
* chore(deps): bump postcss from 8.5.6 to 8.5.14 in /templates by
@​dependabot[bot] in dotnet/docfx#11070
* chore(deps): bump uuid and mermaid in /templates by @​dependabot[bot]
in dotnet/docfx#11073
* chore(deps-dev): bump lodash from 4.17.23 to 4.18.1 in /templates by
@​dependabot[bot] in dotnet/docfx#11061
* chore(deps): bump fast-uri from 3.1.0 to 3.1.2 in /templates by
@​dependabot[bot] in dotnet/docfx#11071
* chore(deps): bump mermaid from 11.15.0 to 11.16.1 in /templates by
@​dependabot[bot] in dotnet/docfx#11093
* chore(deps): bump dompurify from 3.3.1 to 3.4.13 in /templates by
@​dependabot[bot] in dotnet/docfx#11096
* chore(deps-dev): bump js-yaml from 4.1.1 to 4.3.1 in /templates by
@​dependabot[bot] in dotnet/docfx#11095
* chore(deps): bump postcss from 8.5.14 to 8.5.26 in /templates by
@​dependabot[bot] in dotnet/docfx#11094
* chore(deps): bump fast-uri from 3.1.2 to 3.1.5 in /templates by
@​dependabot[bot] in dotnet/docfx#11097
* chore(deps-dev): bump socket.io-parser from 4.2.5 to 4.2.7 in
/templates by @​dependabot[bot] in
dotnet/docfx#11098
* chore(deps): bump ws, engine.io-client, engine.io and
socket.io-adapter in /templates by @​dependabot[bot] in
dotnet/docfx#11101
* chore(deps-dev): bump brace-expansion from 1.1.12 to 1.1.18 in
/templates by @​dependabot[bot] in
dotnet/docfx#11099
* deps: Update playwright version to 1.60.0 by @​filzrev in
dotnet/docfx#11074
* deps: Update roslyn package versions to 5.6.0 by @​filzrev in
dotnet/docfx#11047
* fix(deps): apply compatible npm security updates by @​vicancy in
dotnet/docfx#11105
* Bump the spectre group with 2 updates by @​dependabot[bot] in
dotnet/docfx#11102
* Bump the xunit group with 1 update by @​dependabot[bot] in
dotnet/docfx#11107
* Fix typo in Schema Document Processor overview by @​smartcaveman in
dotnet/docfx#11005
* Bump coverlet.collector from 8.0.0 to 8.0.1 by @​dependabot[bot] in
dotnet/docfx#11045
* chore(deps): bump paulhatch/semantic-version from 6.0.1 to 6.0.2 by
@​dependabot[bot] in dotnet/docfx#11036
* chore(deps): bump dependabot/fetch-metadata from 2.5.0 to 3.0.0 by
@​dependabot[bot] in dotnet/docfx#11051
* chore(deps): bump actions/deploy-pages from 4 to 5 by
@​dependabot[bot] in dotnet/docfx#11049
* chore(deps): bump azure/login from 2 to 3 by @​dependabot[bot] in
dotnet/docfx#11035
* Bump Jint from 4.6.1 to 4.6.3 by @​dependabot[bot] in
dotnet/docfx#11032
* chore(deps): bump dorny/test-reporter from 2.5.0 to 3.0.0 by
@​dependabot[bot] in dotnet/docfx#11043
* Bump AwesomeAssertions from 9.4.0 to 9.5.0 by @​dependabot[bot] in
dotnet/docfx#11114
* chore(deps): bump dependabot/fetch-metadata from 3.0.0 to 3.1.0 by
@​dependabot[bot] in dotnet/docfx#11110
* chore(deps): bump paulhatch/semantic-version from 6.0.2 to 6.0.3 by
@​dependabot[bot] in dotnet/docfx#11112
* chore(deps): bump actions/upload-pages-artifact from 4 to 5 by
@​dependabot[bot] in dotnet/docfx#11109
* chore(deps): bump codecov/codecov-action from 5 to 7 by
@​dependabot[bot] in dotnet/docfx#11113
* chore(deps): bump actions/github-script from 8 to 9 by
@​dependabot[bot] in dotnet/docfx#11111
* Bump the xunit group with 1 update by @​dependabot[bot] in
dotnet/docfx#11117
* Bump coverlet.collector from 8.0.1 to 10.0.1 by @​dependabot[bot] in
dotnet/docfx#11119
* Bump Microsoft.NET.Test.Sdk from 18.0.1 to 18.9.0 by @​dependabot[bot]
in dotnet/docfx#11122
 ... (truncated)

Commits viewable in [compare
view](dotnet/docfx@v2.78.5...v2.80.1).
</details>

[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=docfx&package-manager=nuget&previous-version=2.78.5&new-version=2.80.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
This was referenced Sep 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant