Commit 1ac38d0
UID2-6871: Fix CVE-2026-4800 by upgrading lodash to 4.18.1
Add lodash override (^4.18.0) in package.json overrides for both
react-client-side apps to resolve CVE-2026-4800 in the transitive
lodash@4.17.21 dependency. Regenerated lockfiles confirm lodash@4.18.1
is now installed in place of 4.17.21.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>1 parent 046d1df commit 1ac38d0
4 files changed
Lines changed: 42 additions & 8 deletions
File tree
- web-integrations
- google-secure-signals/react-client-side
- javascript-sdk/react-client-side
Lines changed: 19 additions & 3 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
Lines changed: 2 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
36 | 36 | | |
37 | 37 | | |
38 | 38 | | |
39 | | - | |
| 39 | + | |
| 40 | + | |
40 | 41 | | |
41 | 42 | | |
42 | 43 | | |
| |||
Lines changed: 19 additions & 3 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
Lines changed: 2 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
36 | 36 | | |
37 | 37 | | |
38 | 38 | | |
39 | | - | |
| 39 | + | |
| 40 | + | |
40 | 41 | | |
41 | 42 | | |
42 | 43 | | |
| |||
0 commit comments