fix: pin secure lodash runtime dependency (#44)

This commit is contained in:
xixu-me authored and GitHub committed 2026-04-06 17:59:31 +08:00
1 parent 6bffb98303
commit 7e9a47c949
3 files changed
+16 -3

No files matched your search

+4 -3
View File
@@ -25,6 +25,7 @@
"koa-compress": "^5.2.1",
"langdetect": "^0.2.1",
"linkedom": "^0.18.12",
"lodash": "^4.18.1",
"lru-cache": "^11.2.7",
"maxmind": "^4.3.29",
"minio": "^8.0.7",
@@ -4750,9 +4751,9 @@
}
},
"node_modules/lodash": {
"version": "4.17.23",
"resolved": "https://registry.npmjs.org/lodash/-/lodash-4.17.23.tgz",
"integrity": "sha512-LgVTMpQtIopCi79SJeDiP0TfWi5CNEc/L/aRdTh3yIvmZXTnheWpKjSZhnvMl8iXbC1tFg9gdHHDMLoV7CnG+w==",
"version": "4.18.1",
"resolved": "https://registry.npmjs.org/lodash/-/lodash-4.18.1.tgz",
"integrity": "sha512-dMInicTPVE8d1e5otfwmmjlxkZoUpiVLwyeTdUsi/Caj/gfzzblBcCE5sRHV/AsjuCmxWrte2TNGSYuCeCq+0Q==",
"license": "MIT"
},
"node_modules/lodash.merge": {
+1
View File
@@ -39,6 +39,7 @@
"koa-compress": "^5.2.1",
"langdetect": "^0.2.1",
"linkedom": "^0.18.12",
"lodash": "^4.18.1",
"lru-cache": "^11.2.7",
"maxmind": "^4.3.29",
"minio": "^8.0.7",
+11
View File
@@ -44,3 +44,14 @@ test("security baseline file is present and ready for future exceptions", () =>
assert.ok(Array.isArray(baseline.entries));
assert.equal(baseline.entries.length, 0);
});
test("lodash is declared directly and lockfile avoids the vulnerable 4.17.23 release", () => {
const packageJson = JSON.parse(read("package.json"));
const packageLock = read("package-lock.json");
assert.equal(packageJson.dependencies.lodash, "^4.18.1");
assert.doesNotMatch(
packageLock,
/"node_modules\/lodash":\s*\{[\s\S]*?"version":\s*"4\.17\.23"/,
);
});