From 591c8a04ea8370c42efcb363a46693122101e60f Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Thu, 22 Jan 2026 17:40:12 +0000 Subject: [PATCH 1/2] fix: package.json & yarn.lock to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-LODASH-15053838 --- package.json | 2 +- yarn.lock | 8 ++++---- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/package.json b/package.json index fa8be39..e003251 100644 --- a/package.json +++ b/package.json @@ -19,7 +19,7 @@ "express": "^4.21.2", "formidable": "^3.5.4", "fs-extra": "^11.3.1", - "lodash": "^4.17.21", + "lodash": "^4.17.23", "uuid": "^9.0.1" }, "devDependencies": { diff --git a/yarn.lock b/yarn.lock index 601063c..4867162 100644 --- a/yarn.lock +++ b/yarn.lock @@ -1578,10 +1578,10 @@ lodash.merge@^4.6.2: resolved "https://registry.yarnpkg.com/lodash.merge/-/lodash.merge-4.6.2.tgz#558aa53b43b661e1925a0afdfa36a9a1085fe57a" integrity sha512-0KpjqXRVvrYyCsX1swR/XTK0va6VQkQM6MNo7PqW77ByjAhoARA8EfrP1N4+KlKj8YS0ZUCtRT/YUuhyYDujIQ== -lodash@^4.17.21: - version "4.17.21" - resolved "https://registry.yarnpkg.com/lodash/-/lodash-4.17.21.tgz#679591c564c3bffaae8454cf0b3df370c3d6911c" - integrity sha512-v2kDEe57lecTulaDIuNTPy3Ry4gLGJ6Z1O3vE1krgXZNrsQ+LFTGHVxVjcXPs17LhbZVGedAJv8XZ1tvj5FvSg== +lodash@^4.17.23: + version "4.17.23" + resolved "https://registry.yarnpkg.com/lodash/-/lodash-4.17.23.tgz#f113b0378386103be4f6893388c73d0bde7f2c5a" + integrity sha512-LgVTMpQtIopCi79SJeDiP0TfWi5CNEc/L/aRdTh3yIvmZXTnheWpKjSZhnvMl8iXbC1tFg9gdHHDMLoV7CnG+w== log-symbols@^4.1.0: version "4.1.0" From 9bb021a6af6b3e0883f4690e2584cfc07a5359e6 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Wed, 1 Apr 2026 19:03:08 +0000 Subject: [PATCH 2/2] fix: package.json & yarn.lock to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-LODASH-15053838