Skip to content

Upgrade underscore to address security vulnerability CVE-2026-27601 in underscore#58

Open
xLexip wants to merge 2 commits intocloudfoundry-community:masterfrom
xLexip:CVE-2026-27601
Open

Upgrade underscore to address security vulnerability CVE-2026-27601 in underscore#58
xLexip wants to merge 2 commits intocloudfoundry-community:masterfrom
xLexip:CVE-2026-27601

Conversation

@xLexip
Copy link
Copy Markdown

@xLexip xLexip commented Apr 16, 2026

This updates the underscore dependency to address a security vulnerability with CVSS 8.2. All tests pass and there should be no relevant breaking changes in the underlying dependency. This resolves issue #57.

  • Upgraded the underscore dependency from 1.12.x to 1.13.x in package.json to address CVE-2026-27601 and GHSA-qpx9-hpmf-5gmw.
  • Documented the underscore upgrade and its security context in the README.md changelog.
  • Updated the package version from 1.2.5 to 1.2.6 in package.json to reflect the dependency and security update.
  • Ignored irrelevant files/folders (.idea/ and .DS_Store).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant