From cb52fb4d9e1b2d22cc72807c14dbef4ed0547077 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Sun, 25 Jan 2026 11:17:36 +0000 Subject: [PATCH] fix: package.json & yarn.lock to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-LODASH-15053838 --- package.json | 2 +- yarn.lock | 5 +++++ 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/package.json b/package.json index df49f97f..73c3df1b 100644 --- a/package.json +++ b/package.json @@ -62,7 +62,7 @@ "zone.js": "~0.8.20", "request": "~2.83.0", "hammerjs": "~2.0.8", - "lodash": "~4.17.4", + "lodash": "~4.17.23", "@angularclass/bootloader": "~1.0.1", "@ngrx/store": "~5.1.0", "@ngrx/effects": "~5.1.0", diff --git a/yarn.lock b/yarn.lock index 6bf9b9d3..c57871c9 100644 --- a/yarn.lock +++ b/yarn.lock @@ -6032,6 +6032,11 @@ lodash@^4.0.0, lodash@^4.1.0, lodash@^4.13.1, lodash@^4.14.0, lodash@^4.15.0, lo version "4.17.5" resolved "https://registry.yarnpkg.com/lodash/-/lodash-4.17.5.tgz#99a92d65c0272debe8c96b6057bc8fbfa3bed511" +lodash@~4.17.23: + version "4.17.23" + resolved "https://registry.yarnpkg.com/lodash/-/lodash-4.17.23.tgz#f113b0378386103be4f6893388c73d0bde7f2c5a" + integrity sha512-LgVTMpQtIopCi79SJeDiP0TfWi5CNEc/L/aRdTh3yIvmZXTnheWpKjSZhnvMl8iXbC1tFg9gdHHDMLoV7CnG+w== + log-symbols@^1.0.2: version "1.0.2" resolved "https://registry.yarnpkg.com/log-symbols/-/log-symbols-1.0.2.tgz#376ff7b58ea3086a0f09facc74617eca501e1a18"