Skip to content

chore: resolve Dependabot security alerts (lodash, axios)#27

Merged
craigmorrison merged 1 commit intomainfrom
chore/fix-lodash-vulns
Apr 12, 2026
Merged

chore: resolve Dependabot security alerts (lodash, axios)#27
craigmorrison merged 1 commit intomainfrom
chore/fix-lodash-vulns

Conversation

@craigmorrison
Copy link
Copy Markdown
Owner

Summary

  • lodash: high/critical advisories (_.template code injection, _.unset/_.omit prototype pollution) resolved via lockfile update
  • axios: added npm override pinning axios >=1.15.0 to patch SSRF (NO_PROXY bypass) and cloud-metadata exfiltration advisories reaching us through @module-federation/dts-plugin

Supersedes #15, which was based on the pre-turborepo layout and is no longer applicable.

Test plan

  • `npm audit` reports 0 vulnerabilities
  • CI green
  • `npm run build` — note: `portal-shell-ssr` build is broken on main independently (missing `react-router` dep), unrelated to this change

- lodash: bumped via npm audit fix (transitive update)
- axios: added override to >=1.15.0 to patch SSRF and metadata exfiltration
  advisories pulled in via @module-federation/* dts-plugin

Result: npm audit reports 0 vulnerabilities.
@craigmorrison craigmorrison merged commit 2bd10c4 into main Apr 12, 2026
6 checks passed
@craigmorrison craigmorrison deleted the chore/fix-lodash-vulns branch April 12, 2026 18:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant