Skip to content

Conversation

@uberbinge
Copy link
Contributor

@uberbinge uberbinge commented Feb 5, 2026

Summary

  • Fixes GHSA-xxjr-mmjv-4gpg (lodash-es prototype pollution vulnerability)
  • js-tomlchevrotain@11.0.3lodash-es@4.17.21 is vulnerable
  • Adds yarn resolution to force chevrotain@^11.1.1 which uses patched lodash-es@4.17.23
  • Includes updated yarn.lock

@uberbinge uberbinge force-pushed the fix-lodash-es-vulnerability branch from fe60229 to a9f8dcb Compare February 5, 2026 21:52
Copy link
Contributor

@calavera calavera left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thanks!

@calavera calavera merged commit d0f26f8 into cargo-lambda:main Feb 6, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants