Skip to content

[PR-BOT] [JIRA: GRAL-5895] Fixed vulnerabilities#727

Closed
pipedrive-backoffice-pr[bot] wants to merge 1 commit intomasterfrom
PR-BOT-bcb6502801d5909826fec7b53b970d99529f82ea922d836da04c5320
Closed

[PR-BOT] [JIRA: GRAL-5895] Fixed vulnerabilities#727
pipedrive-backoffice-pr[bot] wants to merge 1 commit intomasterfrom
PR-BOT-bcb6502801d5909826fec7b53b970d99529f82ea922d836da04c5320

Conversation

@pipedrive-backoffice-pr
Copy link
Copy Markdown

Fixed vulnerabilities

Dependency Affected Version Fixed Version Status Reason
picomatch 2.3.1 2.3.2 fixed ✅ fixed by npm audit fix
lodash 4.17.21 4.18.0 fixed ✅ fixed by npm audit fix

Related JIRA ticket:
https://pipedrive.atlassian.net/browse/GRAL-5895

Related Backoffice Task:
https://backoffice.pipedrive.tools/plugins/backoffice-plugin-pr-bot/history?taskId=981

PR was opened by infosec-vulnerability-scanner

@ziimk
Copy link
Copy Markdown
Contributor

ziimk commented May 11, 2026

Closing — lodash 4.18.0 is a deprecated bad release, and the package-lock.json has a merge conflict. Replacing with a clean update to lodash 4.18.1 + npm audit fix from master.

@ziimk ziimk closed this May 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant