Closed dependabot[bot] closed 4 years ago
This probably shouldn't break anything serious, as it seems to only be used within dev dependencies:
$ npm ls lodash
├─┬ @typescript-eslint/parser@2.21.0
│ └─┬ @typescript-eslint/typescript-estree@2.21.0
│ └── lodash@4.17.15 deduped
├─┬ eslint@6.8.0
│ ├─┬ inquirer@7.0.4
│ │ └── lodash@4.17.15 deduped
│ ├── lodash@4.17.15
│ └─┬ table@5.4.6
│ └── lodash@4.17.15 deduped
└─┬ jest@25.1.0
└─┬ @jest/core@25.1.0
├─┬ @jest/reporters@25.1.0
│ └─┬ istanbul-lib-instrument@4.0.1
│ └─┬ @babel/traverse@7.8.4
│ └── lodash@4.17.15 deduped
├─┬ @jest/transform@25.1.0
│ └─┬ @babel/core@7.8.4
│ ├─┬ @babel/generator@7.8.4
│ │ └── lodash@4.17.15 deduped
│ └── lodash@4.17.15 deduped
├─┬ jest-config@25.1.0
│ └─┬ jest-environment-jsdom@25.1.0
│ └─┬ jsdom@15.2.1
│ └─┬ request-promise-native@1.0.8
│ └─┬ request-promise-core@1.1.3
│ └── lodash@4.17.15 deduped
└─┬ jest-snapshot@25.1.0
└─┬ @babel/types@7.8.3
└── lodash@4.17.15 deduped
Looks good to me. I'll merge and update the npm package in a little bit 👍 Thanks @bradtaniguchi !
Bumps lodash from 4.17.15 to 4.17.19.
Release notes
Sourced from lodash's releases.
Commits
d7fbc52
Bump to v4.17.192e1c0f2
Add npm-package1b6c282
Bump to v4.17.18a370ac8
Bump to v4.17.171144918
Rebuild lodash and docs3a3b0fd
Bump to v4.17.16c84fe82
fix(zipObjectDeep): prototype pollution (#4759)e7b28ea
Sanitize sourceURL so it cannot affect evaled code (#4518)0cec225
Fix lodash.isEqual for circular references (#4320) (#4515)94c3a81
Document matches* shorthands for over* methods (#4510) (#4514)Maintainer changes
This version was pushed to npm by mathias, a new releaser for lodash since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/JLuboff/connect-mssql-v2/network/alerts).