Skip to content

fix(deps): bump lodash to >=4.18.0 (Dependabot #26, #27)#7

Closed
ibuildthings-instrumentl wants to merge 1 commit intodevfrom
fix/dependabot-lodash
Closed

fix(deps): bump lodash to >=4.18.0 (Dependabot #26, #27)#7
ibuildthings-instrumentl wants to merge 1 commit intodevfrom
fix/dependabot-lodash

Conversation

@ibuildthings-instrumentl
Copy link
Copy Markdown
Collaborator

Summary

Vulnerabilities fixed

Changes

  • package.json: Added "lodash": "^4.18.0" to overrides
  • bun.lock: Updated lockfile (lodash now resolves to 4.18.1)

Test plan

  • bun install succeeds
  • lockfile resolves lodash to 4.18.1
  • CI passes (type-check, lint, format, tests)

🤖 Generated with Claude Code

…, coleam00#27)

Adds a Bun override to force lodash >=4.18.0 for all transitive
consumers. lodash is pulled in transitively via @sapphire/shapeshift
(discord.js dependency).

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@ibuildthings-instrumentl
Copy link
Copy Markdown
Collaborator Author

Closing to recreate on top of latest dev (avoid merge conflicts)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant