Conversation
Bumps the npm_and_yarn group with 1 update in the / directory: [lodash-es](https://github.com/lodash/lodash). Updates `lodash-es` from 4.17.23 to 4.18.1 - [Release notes](https://github.com/lodash/lodash/releases) - [Commits](lodash/lodash@4.17.23...4.18.1) --- updated-dependencies: - dependency-name: lodash-es dependency-version: 4.18.1 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
…arn-7d3393088f chore(deps): Bump lodash-es from 4.17.23 to 4.18.1 in the npm_and_yarn group across 1 directory
Bumps the npm_and_yarn group with 1 update in the / directory: [lodash](https://github.com/lodash/lodash). Updates `lodash` from 4.17.23 to 4.18.1 - [Release notes](https://github.com/lodash/lodash/releases) - [Commits](lodash/lodash@4.17.23...4.18.1) --- updated-dependencies: - dependency-name: lodash dependency-version: 4.18.1 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
…arn-52571dc7e9 chore(deps): Bump lodash from 4.17.23 to 4.18.1 in the npm_and_yarn group across 1 directory
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
DeepSource Code ReviewWe reviewed changes in See full review on DeepSource ↗ Code Review Summary
Important AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
There was a problem hiding this comment.
Code Review
This pull request updates the versions of lodash and lodash-es in package-lock.json to 4.18.1. Feedback indicates that these versions do not exist on the public npm registry and may represent a security risk via dependency confusion. It is recommended to revert to a valid stable version like 4.17.21 to ensure build stability and security.
No description provided.