Bug#1141449: trixie-pu: package node-lodash/4.17.21+dfsg+~cs8.31.198.20210220-9+deb13u1

Utkarsh Gupta <[email protected]>
Newsgroups gmane.linux.debian.devel.release
Message-ID <CAPP0f952qdiaERUrDX3rR8U7m+3xpmMy5k-CzUMTmk_5fvSKFQ__37355.6962747657$1783207047$gmane$org@mail.gmail.com>
Package: release.debian.org
User: [email protected]
Usertags: pu
Tags: trixie
X-Debbugs-CC: [email protected]
Severity: normal

Hi,

node-lodash is affected by 3 open CVEs (CVE-2025-13465, CVE-2026-2950,
and CVE-2026-4800). This has been fixed in sid, forky, and bullseye.
Only bookworm and trixie remain, as shown in the tracker:

https://security-tracker.debian.org/tracker/source-package/node-lodash.

Attaching the debdiff for trixie -pu. I'll wait for your ACK before
uploading the package. Let me know if you have any questions or
concerns.


- u
node-lodash-trixie.debdiff (application/octet-stream, 27.3 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.