Skip to content

build(deps-dev): bump lodash from 4.17.21 to 4.17.23#220

Merged
allenkinzalow merged 2 commits intodependabot/npm_and_yarn/lodash-4.17.23from
copilot/sub-pr-211
Mar 11, 2026
Merged

build(deps-dev): bump lodash from 4.17.21 to 4.17.23#220
allenkinzalow merged 2 commits intodependabot/npm_and_yarn/lodash-4.17.23from
copilot/sub-pr-211

Conversation

Copy link
Contributor

Copilot AI commented Mar 11, 2026

Bumps lodash from 4.17.21 to 4.17.23 to pick up security fixes.

Description

  • Dependency version bump: lodash 4.17.21 → 4.17.23
  • Adds patch changeset documenting the upgrade

Checklist

  • Tests added for changes
  • Changeset added

💡 You can make Copilot smarter by setting up custom instructions, customizing its development environment and configuring Model Context Protocol (MCP) servers. Learn more Copilot coding agent tips in the docs.

Co-authored-by: allenkinzalow <2922507+allenkinzalow@users.noreply.github.com>
Copilot AI changed the title [WIP] Update lodash dependency from 4.17.21 to 4.17.23 build(deps-dev): bump lodash from 4.17.21 to 4.17.23 Mar 11, 2026
@allenkinzalow allenkinzalow marked this pull request as ready for review March 11, 2026 03:53
Copilot AI review requested due to automatic review settings March 11, 2026 03:53
@allenkinzalow allenkinzalow merged commit e0c2753 into dependabot/npm_and_yarn/lodash-4.17.23 Mar 11, 2026
@allenkinzalow allenkinzalow deleted the copilot/sub-pr-211 branch March 11, 2026 03:53
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR documents a dev-dependency security update by adding a Changesets entry for the Lodash upgrade.

Changes:

  • Add a patch changeset describing the Lodash update to 4.17.23.

You can also share your feedback on Copilot code review. Take the survey.

"@osrs-wiki/cache-mediawiki": patch
---

bump lodash from 4.17.21 to 4.17.23
Copy link

Copilot AI Mar 11, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The changeset summary is a bit unclear/inconsistent: it starts with a lowercase “bump” and implies a direct dependency update, but lodash isn’t listed in package.json (so this is likely a lockfile/transitive resolution change). Consider capitalizing the sentence and clarifying that this updates the resolved lodash version to 4.17.23 for security fixes.

Suggested change
bump lodash from 4.17.21 to 4.17.23
Update the resolved transitive lodash dependency from 4.17.21 to 4.17.23 to address security fixes.

Copilot uses AI. Check for mistakes.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants