Skip to content

Conversation

@emizzle
Copy link
Contributor

@emizzle emizzle commented Jul 11, 2019

Update lodash.defaultsdeep to version ^4.6.1.

This is causing a high severity vulnerability in our repo.

Fixed in lodash/lodash#4336.

@haoqunjiang
Copy link
Member

Would you please exclude yarn.lock from the commit? Because otherwise it would be hard for us to cherry-pick this PR to other branches.

Update `lodash.defaultsdeep` to version `^4.6.1`.

This is causing a high severity vulnerability in our repo.

Fixed in lodash/lodash#4336.
@emizzle emizzle force-pushed the fix/deps/update-lodash.defaultsdeep branch from ed34b96 to bb51a67 Compare July 11, 2019 07:34
@emizzle
Copy link
Contributor Author

emizzle commented Jul 11, 2019

@sodatea Done.

@haoqunjiang haoqunjiang merged commit 4267b54 into vuejs:v3 Jul 11, 2019
@vue-bot
Copy link

vue-bot commented Jul 11, 2019

Hey @emizzle, thank you for your time and effort spent on this PR, contributions like yours help make Vue better for everyone. Cheers! 💚

haoqunjiang pushed a commit that referenced this pull request Jul 11, 2019
Update `lodash.defaultsdeep` to version `^4.6.1`.

This is causing a high severity vulnerability in our repo.

Fixed in lodash/lodash#4336.

(cherry picked from commit 4267b54)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants