Skip to content

chore(deps-dev): bump lodash from 4.17.23 to 4.18.1 in /src/LoggerUsage.VSCode#226

Merged
Meir017 merged 1 commit intomainfrom
dependabot/npm_and_yarn/src/LoggerUsage.VSCode/lodash-4.18.1
Apr 8, 2026
Merged

chore(deps-dev): bump lodash from 4.17.23 to 4.18.1 in /src/LoggerUsage.VSCode#226
Meir017 merged 1 commit intomainfrom
dependabot/npm_and_yarn/src/LoggerUsage.VSCode/lodash-4.18.1

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 8, 2026

Bumps lodash from 4.17.23 to 4.18.1.

Release notes

Sourced from lodash's releases.

4.18.1

Bugs

Fixes a ReferenceError issue in lodash lodash-es lodash-amd and lodash.template when using the template and fromPairs functions from the modular builds. See lodash/lodash#6167

These defects were related to how lodash distributions are built from the main branch using https://github.com/lodash-archive/lodash-cli. When internal dependencies change inside lodash functions, equivalent updates need to be made to a mapping in the lodash-cli. (hey, it was ahead of its time once upon a time!). We know this, but we missed it in the last release. It's the kind of thing that passes in CI, but fails bc the build is not the same thing you tested.

There is no diff on main for this, but you can see the diffs for each of the npm packages on their respective branches:

4.18.0

v4.18.0

Full Changelog: lodash/lodash@4.17.23...4.18.0

Security

_.unset / _.omit: Fixed prototype pollution via constructor/prototype path traversal (GHSA-f23m-r3pf-42rh, fe8d32e). Previously, array-wrapped path segments and primitive roots could bypass the existing guards, allowing deletion of properties from built-in prototypes. Now constructor and prototype are blocked unconditionally as non-terminal path keys, matching baseSet. Calls that previously returned true and deleted the property now return false and leave the target untouched.

_.template: Fixed code injection via imports keys (GHSA-r5fr-rjxr-66jc, CVE-2026-4800, 879aaa9). Fixes an incomplete patch for CVE-2021-23337. The variable option was validated against reForbiddenIdentifierChars but importsKeys was left unguarded, allowing code injection via the same Function() constructor sink. imports keys containing forbidden identifier characters now throw "Invalid imports option passed into _.template".

Docs

  • Add security notice for _.template in threat model and API docs (#6099)
  • Document lower > upper behavior in _.random (#6115)
  • Fix quotes in _.compact jsdoc (#6090)

lodash.* modular packages

Diff

We have also regenerated and published a select number of the lodash.* modular packages.

These modular packages had fallen out of sync significantly from the minor/patch updates to lodash. Specifically, we have brought the following packages up to parity w/ the latest lodash release because they have had CVEs on them in the past:

Commits
  • cb0b9b9 release(patch): bump main to 4.18.1 (#6177)
  • 75535f5 chore: prune stale advisory refs (#6170)
  • 62e91bc docs: remove n_ Node.js < 6 REPL note from README (#6165)
  • 59be2de release(minor): bump to 4.18.0 (#6161)
  • af63457 fix: broken tests for _.template 879aaa9
  • 1073a76 fix: linting issues
  • 879aaa9 fix: validate imports keys in _.template
  • fe8d32e fix: block prototype pollution in baseUnset via constructor/prototype traversal
  • 18ba0a3 refactor(fromPairs): use baseAssignValue for consistent assignment (#6153)
  • b819080 ci: add dist sync validation workflow (#6137)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [lodash](https://github.com/lodash/lodash) from 4.17.23 to 4.18.1.
- [Release notes](https://github.com/lodash/lodash/releases)
- [Commits](lodash/lodash@4.17.23...4.18.1)

---
updated-dependencies:
- dependency-name: lodash
  dependency-version: 4.18.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Apr 8, 2026
@github-actions
Copy link
Copy Markdown

github-actions Bot commented Apr 8, 2026

Summary

Summary
Generated on: 04/08/2026 - 18:11:37
Parser: MultiReport (3x Cobertura)
Assemblies: 4
Classes: 61
Files: 58
Line coverage: 79.4% (2935 of 3693)
Covered lines: 2935
Uncovered lines: 758
Coverable lines: 3693
Total lines: 6335
Branch coverage: 66.5% (988 of 1485)
Covered branches: 988
Total branches: 1485
Method coverage: Feature is only available for sponsors

Coverage

LoggerUsage - 80%
Name Line Branch
LoggerUsage 80% 66.4%
LoggerUsage.Analyzers.BeginScopeAnalyzer 90% 87.5%
LoggerUsage.Analyzers.EventIdExtractor 82.2% 78.5%
LoggerUsage.Analyzers.LocationHelper 100% 50%
LoggerUsage.Analyzers.LoggerMessageAttributeAnalyzer 85.1% 77.5%
LoggerUsage.Analyzers.LoggerMessageAttributeAnalyzer.LoggerMessageDeclarati
on
100%
LoggerUsage.Analyzers.LoggerMessageDefineAnalyzer 95.7% 85.7%
LoggerUsage.Analyzers.LogMethodAnalyzer 91.9% 75.8%
LoggerUsage.LoggerExtensionModeler 84.8% 82.5%
LoggerUsage.LoggerUsageExtractor 88.8% 76.1%
LoggerUsage.LoggerUsageSummarizer 86.8% 82.7%
LoggerUsage.LoggerUsageSummarizer.NameTypePairListComparer 60.8% 50%
LoggerUsage.LoggingTypes 100%
LoggerUsage.LogValuesFormatter 92.1% 95.8%
LoggerUsage.MessageTemplate.IMessageTemplateExtractor 100%
LoggerUsage.MessageTemplate.MessageTemplateExtractor 100% 77.7%
LoggerUsage.Models.ConstantOrReference 100%
LoggerUsage.Models.DataClassificationInfo 0%
LoggerUsage.Models.EventIdDetails 100%
LoggerUsage.Models.EventIdRef 100%
LoggerUsage.Models.LoggerMessageInvocation 100%
LoggerUsage.Models.LoggerMessageUsageInfo 100% 100%
LoggerUsage.Models.LoggerUsageExtractionResult 100%
LoggerUsage.Models.LoggerUsageExtractionSummary 100% 87.5%
LoggerUsage.Models.LoggerUsageExtractionSummary.ClassificationStatistics 100% 50%
LoggerUsage.Models.LoggerUsageExtractionSummary.TelemetryStatistics 100% 100%
LoggerUsage.Models.LoggerUsageInfo 100%
LoggerUsage.Models.LoggerUsageProgress 100% 100%
LoggerUsage.Models.LoggingAnalysisContext 84.2% 50%
LoggerUsage.Models.LogPropertiesConfiguration 100%
LoggerUsage.Models.LogPropertiesParameterInfo 100%
LoggerUsage.Models.LogPropertyInfo 100%
LoggerUsage.Models.MessageParameter 100%
LoggerUsage.Models.ScopeAnalysisResult 58.8%
LoggerUsage.Models.TagProviderInfo 100%
LoggerUsage.ParameterExtraction.AnonymousObjectParameterExtractor 78.9% 62.5%
LoggerUsage.ParameterExtraction.ArrayParameterExtractor 85.7% 72.2%
LoggerUsage.ParameterExtraction.GenericTypeParameterExtractor 100% 100%
LoggerUsage.ParameterExtraction.MethodSignatureParameterExtractor 90.2% 100%
LoggerUsage.ReportGenerator.HtmlLoggerReportGenerator 67.5% 32.9%
LoggerUsage.ReportGenerator.JsonLoggerReportGenerator 100% 50%
LoggerUsage.ReportGenerator.LoggerReportGeneratorFactory 85.7% 75%
LoggerUsage.ReportGenerator.MarkdownLoggerReportGenerator 72.2% 48.1%
LoggerUsage.Services.KeyValuePairExtractionService 76.1% 56.6%
LoggerUsage.Services.ProgressReporter 93.5% 88.8%
LoggerUsage.Services.ScopeAnalysisService 73.9% 76.1%
LoggerUsage.Utilities.DataClassificationExtractor 13.4% 6.6%
LoggerUsage.Utilities.MessageParameterFactory 100% 100%
LoggerUsage.Utilities.OperationExtensions 100% 100%
LoggerUsage.Utilities.SymbolExtensions 95.4% 87.5%
LoggerUsage.Utilities.WorkspaceHelper 82.2% 75%
Microsoft.Extensions.DependencyInjection.LoggerUsageBuilderExtensions 100%
Microsoft.Extensions.DependencyInjection.LoggerUsageBuilderExtensions.Logge
rUsageBuilder
100%
LoggerUsage.Cli - 58%
Name Line Branch
LoggerUsage.Cli 58% 63.8%
LoggerUsage.Cli.LoggerUsageWorker 87.5% 72.2%
LoggerUsage.Cli.Program 85.1% 83.3%
LoggerUsage.Cli.ProgressBarHandler 0% 0%
LoggerUsage.Mcp - 87.8%
Name Line Branch
LoggerUsage.Mcp 87.8% 70%
LoggerUsage.Mcp.McpProgressAdapter 80% 62.5%
LoggerUsageExtractorTool 100% 100%
Program 100%
LoggerUsage.MSBuild - 79%
Name Line Branch
LoggerUsage.MSBuild 79% 75%
LoggerUsage.MSBuild.MSBuildWorkspaceFactory 77.3% 75%
LoggerUsage.MSBuild.MSBuildWorkspaceFactory.ProjectProgress 100%
Microsoft.Extensions.DependencyInjection.LoggerUsageMSBuildBuilderExtension
s
100%

@Meir017 Meir017 merged commit fc98255 into main Apr 8, 2026
6 checks passed
@Meir017 Meir017 deleted the dependabot/npm_and_yarn/src/LoggerUsage.VSCode/lodash-4.18.1 branch April 8, 2026 18:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant