Skip to content

[GHSA-p6mc-m468-83gw] Prototype Pollution in lodash #5978

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: G-Rath/advisory-improvement-5978
Choose a base branch
from

Conversation

G-Rath
Copy link

@G-Rath G-Rath commented Aug 10, 2025

Updates

  • Affected products

Comments
Added lodash-rails to list of impacted packages

@Copilot Copilot AI review requested due to automatic review settings August 10, 2025 19:20
Copy link

@Copilot Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR updates a GitHub Security Advisory (GHSA-p6mc-m468-83gw) for a prototype pollution vulnerability in lodash by adding lodash-rails to the list of affected packages.

  • Updated the modification timestamp to reflect the advisory change
  • Added lodash-rails package from the RubyGems ecosystem as an affected package with the same vulnerability range

"introduced": "0"
},
{
"fixed": "4.17.21"
Copy link
Preview

Copilot AI Aug 10, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The fixed version "4.17.21" for lodash-rails may be incorrect. This appears to be a lodash version number, but lodash-rails is a separate RubyGems package that wraps lodash and likely has its own versioning scheme. Please verify the correct fixed version for the lodash-rails package.

Suggested change
"fixed": "4.17.21"

Copilot uses AI. Check for mistakes.

Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It is the correct version - the gems versioning matches the version of lodash that it provides (at least in the 4.x line)

@github-actions github-actions bot changed the base branch from main to G-Rath/advisory-improvement-5978 August 10, 2025 19:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant