10BC0 4766 bump lodash 4.17.20 > 4.17.21 by rfultz · Pull Request #4782 · fecgov/openFEC · GitHub
[go: up one dir, main page]

Skip to content

Conversation

@rfultz
Copy link
Contributor
@rfultz rfultz commented Feb 24, 2021

Summary

Reviewers

Feel free to add/remove

Impacted areas of the application

Bumped the version of lodash from 4.17.20 to 4.17.21, just a patch-level change

Screenshots

None

Related PRs

None

How to test

  • pull branch
  • npm i
  • npm run build will tell us if lodash failed as a devDependency
  • ./manage.py runserver
  • localhost should work as expected
  • Looking at the release notes for lodash, it looks like only trim() and baseTrim() were affected and they were used by isNumber(). It doesn't looks like swagger-tools is using any of the three

Copy link
Contributor
@pkfec pkfec left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

Copy link
Member
@lbeaufort lbeaufort left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, @rfultz!

@lbeaufort lbeaufort merged commit 20acaa5 into develop Feb 26, 2021
@lbeaufort lbeaufort deleted the feature/4766-snyk-lodash branch February 26, 2021 19:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Snyk: High] Command Injection (due 3/19/21)

4 participants

0