scm-automation-project / npm-6-with-lock-file-project

0 stars 0 forks source link

Update dependency lodash to v4.17.21 - autoclosed #25

Closed dev-mend-for-github-com[bot] closed 2 years ago

dev-mend-for-github-com[bot] commented 2 years ago

This PR contains the following updates:

Package Type Update Change
lodash (source) dependencies patch 4.17.15 -> 4.17.21

By merging this PR, the issue #19 will be automatically resolved and closed:

Severity CVSS Score CVE
High High 7.4 CVE-2020-8203
High High 7.2 CVE-2021-23337
Medium Medium 5.3 CVE-2020-28500

Release Notes

lodash/lodash ### [`v4.17.21`](https://togithub.com/lodash/lodash/compare/4.17.20...4.17.21) [Compare Source](https://togithub.com/lodash/lodash/compare/4.17.20...4.17.21) ### [`v4.17.20`](https://togithub.com/lodash/lodash/compare/4.17.19...4.17.20) [Compare Source](https://togithub.com/lodash/lodash/compare/4.17.19...4.17.20) ### [`v4.17.16`](https://togithub.com/lodash/lodash/compare/4.17.15...4.17.16) [Compare Source](https://togithub.com/lodash/lodash/compare/4.17.15...4.17.16)