Skip to content

fix(security): replace deprecated trivy --vuln-type flag and ignore lodash CVE#65

Merged
jdoucy merged 1 commit intomainfrom
63-fix-lodash-cve-2026-4800
Apr 2, 2026
Merged

fix(security): replace deprecated trivy --vuln-type flag and ignore lodash CVE#65
jdoucy merged 1 commit intomainfrom
63-fix-lodash-cve-2026-4800

Conversation

@jdoucy
Copy link
Copy Markdown
Member

@jdoucy jdoucy commented Apr 2, 2026

No description provided.

…odash CVE

- replace --vuln-type with --pkg-types in Makefile, CI workflow, and docs
- add CVE-2026-4800 (lodash 4.17.23) to .trivyignore.yaml — fix in 4.18.1, blocked on upstream deps
@jdoucy jdoucy linked an issue Apr 2, 2026 that may be closed by this pull request
@vercel
Copy link
Copy Markdown

vercel bot commented Apr 2, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
connect-web Ready Ready Preview, Comment Apr 2, 2026 3:56pm

Request Review

@jdoucy jdoucy merged commit fe65744 into main Apr 2, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Fix lodash CVE-2026-4800

1 participant