## Description This PR enforces lodash version 4.17.21 or above, mitigating the **Critical severity** vulnerability [CVE-2019-10744](https://github.com/advisories/GHSA-jf85-cpcp-j695). ## Automation /ok-to-test tags="@tag.Sanity" ### 🔍 Cypress test results <!-- This is an auto-generated comment: Cypress test results --> > [!CAUTION] > If you modify the content in this section, you are likely to disrupt the CI result for your PR. <!-- end of auto-generated comment: Cypress test results --> ## Communication Should the DevRel and Marketing teams inform users about this change? - [ ] Yes - [x] No <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Chores** - Updated the version constraints for the lodash library across multiple packages. This ensures a minimum version of 4.17.21 while allowing a broader range of updates, including potential major releases. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
24 lines
672 B
JSON
24 lines
672 B
JSON
{
|
|
"name": "@appsmith/wds-theming",
|
|
"version": "1.0.0",
|
|
"main": "src/index.ts",
|
|
"author": "Valera Melnikov <valera@appsmith.com>, Pawan Kumar <pawan@appsmith.com>",
|
|
"license": "MIT",
|
|
"scripts": {
|
|
"lint": "yarn g:lint",
|
|
"prettier": "yarn g:prettier",
|
|
"build:tokens": "npx ts-node ./src/utils/tokensToJson.ts && npx ts-node ./src/utils/tokensToCss.ts",
|
|
"test:unit": "yarn g:jest"
|
|
},
|
|
"peerDependencies": {
|
|
"react": "^16.8.0 || ^17.0.0-rc.1 || ^18.0.0"
|
|
},
|
|
"dependencies": {
|
|
"@capsizecss/core": "^3.1.1",
|
|
"@capsizecss/metrics": "^1.2.0",
|
|
"@emotion/css": "^11.13.0",
|
|
"colorjs.io": "^0.5.2",
|
|
"lodash": ">=4.17.21"
|
|
}
|
|
}
|