Skip to content

chore(deps): bump immutable from 5.1.4 to 5.1.5#560

Open
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/npm_and_yarn/immutable-5.1.5
Open

chore(deps): bump immutable from 5.1.4 to 5.1.5#560
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/npm_and_yarn/immutable-5.1.5

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Mar 5, 2026

Bumps immutable from 5.1.4 to 5.1.5.

Release notes

Sourced from immutable's releases.

v5.1.5

What's Changed

Full Changelog: immutable-js/immutable-js@v5.1.4...v5.1.5

Changelog

Sourced from immutable's changelog.

5.1.5

  • Fix Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in immutable
Commits
  • b37b855 5.1.5
  • 16b3313 Merge commit from fork
  • fd2ef49 fix new proto key injection
  • 6734b7b fix Prototype Pollution in mergeDeep, toJS, etc.
  • 6f772de Merge pull request #2175 from immutable-js/dependabot/npm_and_yarn/rollup-4.59.0
  • 5f3dc61 Bump rollup from 4.34.8 to 4.59.0
  • 049a594 Merge pull request #2173 from immutable-js/dependabot/npm_and_yarn/lodash-4.1...
  • 2481a77 Merge pull request #2172 from mrazauskas/update-tstyche
  • eb04779 Bump lodash from 4.17.21 to 4.17.23
  • b973bf3 format
  • Additional commits viewable in compare view

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot bot commented on behalf of github Mar 5, 2026

Labels

The following labels could not be found: dependabot. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Mar 5, 2026
@dependabot dependabot bot requested a review from a team as a code owner March 5, 2026 00:03
@dependabot dependabot bot requested review from separatrixxx and removed request for a team March 5, 2026 00:03
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Mar 5, 2026
@yc-ui-bot
Copy link
Copy Markdown
Contributor

Visual Tests Report is ready.

@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/immutable-5.1.5 branch from 3d63ef8 to 1d8d0ce Compare March 19, 2026 11:33
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/immutable-5.1.5 branch 2 times, most recently from f7ac320 to 38e895f Compare April 1, 2026 12:54
Bumps [immutable](https://github.com/immutable-js/immutable-js) from 5.1.4 to 5.1.5.
- [Release notes](https://github.com/immutable-js/immutable-js/releases)
- [Changelog](https://github.com/immutable-js/immutable-js/blob/main/CHANGELOG.md)
- [Commits](immutable-js/immutable-js@v5.1.4...v5.1.5)

---
updated-dependencies:
- dependency-name: immutable
  dependency-version: 5.1.5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/immutable-5.1.5 branch from 38e895f to d066631 Compare April 2, 2026 13:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant