fix(cve): CVE-2025-13465 - lodash - #269
Conversation
- Add npm override for lodash to force version ^4.17.23 - Fixes prototype pollution in _.unset and _.omit functions - Affects transitive dependency in Web UI Resolves: ACM-29057 Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: coleenquadros The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
- Regenerate compressed .gz assets after lodash override - Update embed.go with new asset manifest - Ensures built artifacts match the dependency update Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
|
@coleenquadros: The following test failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
Summary
Fixes CVE-2025-13465 by adding an npm override for lodash to force v4.17.23+.
CVE Details
Changes
overrides.lodash: "^4.17.23"toweb/ui/package.jsonpackage-lock.jsonto resolve lodash 4.17.23+Risk Assessment
Low — lodash patch version bump via npm overrides
Resolves: ACM-29057
🤖 Generated by CVE Fixer Workflow