Skip to content

test: add vulnerable lodash@4.17.4 to verify dependency-review action#69

Open
ragarwal-spreedly wants to merge 1 commit into
mainfrom
test/dep-review-verification
Open

test: add vulnerable lodash@4.17.4 to verify dependency-review action#69
ragarwal-spreedly wants to merge 1 commit into
mainfrom
test/dep-review-verification

Conversation

@ragarwal-spreedly
Copy link
Copy Markdown
Contributor

@ragarwal-spreedly ragarwal-spreedly commented Apr 29, 2026

This commit intentionally adds a known-vulnerable dependency (lodash 4.17.4 has multiple high/critical CVEs) to verify that the new dependency-review GitHub Action correctly fails CI.

This PR is for verification only and should NOT be merged.

This commit intentionally adds a known-vulnerable dependency
(lodash 4.17.4 has multiple high/critical CVEs) to verify that
the new dependency-review GitHub Action correctly fails CI.

This PR is for verification only and should NOT be merged.

Made-with: Cursor
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant