diff --git a/package-lock.json b/package-lock.json index 3f20a01..982b56d 100644 --- a/package-lock.json +++ b/package-lock.json @@ -25,6 +25,7 @@ "koa-compress": "^5.2.1", "langdetect": "^0.2.1", "linkedom": "^0.18.12", + "lodash": "^4.18.1", "lru-cache": "^11.2.7", "maxmind": "^4.3.29", "minio": "^8.0.7", @@ -4750,9 +4751,9 @@ } }, "node_modules/lodash": { - "version": "4.17.23", - "resolved": "https://registry.npmjs.org/lodash/-/lodash-4.17.23.tgz", - "integrity": "sha512-LgVTMpQtIopCi79SJeDiP0TfWi5CNEc/L/aRdTh3yIvmZXTnheWpKjSZhnvMl8iXbC1tFg9gdHHDMLoV7CnG+w==", + "version": "4.18.1", + "resolved": "https://registry.npmjs.org/lodash/-/lodash-4.18.1.tgz", + "integrity": "sha512-dMInicTPVE8d1e5otfwmmjlxkZoUpiVLwyeTdUsi/Caj/gfzzblBcCE5sRHV/AsjuCmxWrte2TNGSYuCeCq+0Q==", "license": "MIT" }, "node_modules/lodash.merge": { diff --git a/package.json b/package.json index 8cceb26..ff67489 100644 --- a/package.json +++ b/package.json @@ -39,6 +39,7 @@ "koa-compress": "^5.2.1", "langdetect": "^0.2.1", "linkedom": "^0.18.12", + "lodash": "^4.18.1", "lru-cache": "^11.2.7", "maxmind": "^4.3.29", "minio": "^8.0.7", diff --git a/tests/security-governance.test.cjs b/tests/security-governance.test.cjs index 7b0918a..5c5d85d 100644 --- a/tests/security-governance.test.cjs +++ b/tests/security-governance.test.cjs @@ -44,3 +44,14 @@ test("security baseline file is present and ready for future exceptions", () => assert.ok(Array.isArray(baseline.entries)); assert.equal(baseline.entries.length, 0); }); + +test("lodash is declared directly and lockfile avoids the vulnerable 4.17.23 release", () => { + const packageJson = JSON.parse(read("package.json")); + const packageLock = read("package-lock.json"); + + assert.equal(packageJson.dependencies.lodash, "^4.18.1"); + assert.doesNotMatch( + packageLock, + /"node_modules\/lodash":\s*\{[\s\S]*?"version":\s*"4\.17\.23"/, + ); +});