fix(deps): bump lodash and lodash-es to 4.18.1 (CVE-2021-23337) - #235
Open
focuslight-nr wants to merge 2 commits into
Open
focuslight-nr wants to merge 2 commits into
focuslight-nr wants to merge 2 commits into
Conversation
lodash and lodash-es 4.17.21 are affected by CVE-2021-23337 (command injection in `template`, EPSS ~21%), CVE-2025-13465, CVE-2026-2950 and CVE-2026-4800. Every range that reaches them already allows 4.18.x (recharts ^4.17.21, force-graph/kapsule lodash-es 4, the conventional- changelog tooling ^4.17.15), so this is a lockfile-only change with no package.json edits. Only those two entries were re-resolved; `yarn upgrade` was not used because it ignores transitive packages in a workspace and drags in unrelated bumps. The one remaining lodash 4.17.21 is commitizen's exact pin (dev-only commit tooling); commitizen 4.3.2 moves that pin to 4.18.1 but also pulls in @commitlint 21, so it is left for a separate change. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…kfile flowsint-app/Dockerfile (used by docker-compose with context ./flowsint-app) installs from flowsint-app/yarn.lock, not the root lockfile, so the root bump alone does not reach the built image. Same two entries, spliced in unchanged from the root lockfile. A plain `yarn install` in a standalone copy of flowsint-app - what the Dockerfile runs - now resolves lodash and lodash-es to 4.18.1 (4.17.21 before). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Bumps
lodashandlodash-esfrom 4.17.21 to 4.18.1 in both lockfiles. Lockfile-only: every range that reaches them already allows 4.18.x (recharts^4.17.21,force-graph/kapsulelodash-es@4, the conventional-changelog tooling^4.17.15), so nopackage.jsonchanges.Why
4.17.21 is affected by CVE-2021-23337 (command injection via
_.template, EPSS ≈ 21%), plus CVE-2025-13465, CVE-2026-2950 and CVE-2026-4800.rechartspullslodashinto the app's production bundle, andlodash-escomes in through the graph view (force-graph/kapsule).Two lockfiles, two commits
a8cf218rootyarn.lock– what CI and local dev use (yarn install --frozen-lockfile).b700942flowsint-app/yarn.lock–flowsint-app/Dockerfileis built with context./flowsint-appindocker-compose.yml, so the image installs from this file, not the root one. The root bump alone would not reach the image.Only those two lock entries were re-resolved, and the same entries were used in both files.
yarn upgradewas avoided because in a workspace it silently skips transitive packages and pulls in unrelated bumps.Verification
yarn install --frozen-lockfilepasses at the root.flowsint-app:npx vitest run(15 passed) andyarn buildsucceed.yarn installin a standalone copy offlowsint-app/(what the Dockerfile runs) installslodash4.18.1 andlodash-es4.18.1. The same steps onmaininstall 4.17.21.Run locally on Node 26; CI uses 22.
Not in this PR
commitizenstill pinslodash4.17.21 exactly. It is dev-only commit tooling, so nothing ships with it.commitizen4.3.2 (within the declared^4.3.1) moves the pin to 4.18.1 but also brings in@commitlint21 and ~30 other changes, so it seemed better as its own PR.flowsint-app/yarn.lockis out of sync withflowsint-app/package.json. It was last updated in Oct 2025, andyarn install --frozen-lockfilefails against it. Because the Dockerfile runsyarn installwithout--frozen-lockfile, every image build quietly re-resolves the difference (about 3.5k lockfile lines), so the image isn't pinned to anything reviewed. Scanners that read that lockfile directly will also keep flagging the orphanedlodash@4.17.21entry that belongs to stalecommitizenentries, even though a real install prunes it. Possible fixes are regenerating it, or building the image from the repo root against the root lockfile. That is a design decision, so I've left it to you.🤖 Generated with Claude Code