Bug#1141450: bookworm-pu: package node-lodash/4.17.21+dfsg+~cs8.31.198.20210220-9+deb12u1
Utkarsh Gupta <[email protected]>
| Newsgroups | gmane.linux.debian.devel.release |
|---|---|
| Message-ID | <CAPP0f96MQZ2XDgGRXeTEwo3p8frB5UQbSOcWxMLnUhf8DfLbow__639.103951264985$1783207051$gmane$org@mail.gmail.com> |
Package: release.debian.org User: [email protected] Usertags: pu Tags: bookworm X-Debbugs-CC: [email protected] Severity: normal Hi, node-lodash is affected by 3 open CVEs (CVE-2025-13465, CVE-2026-2950, and CVE-2026-4800). This has been fixed in sid, forky, and bullseye. Only bookworm and trixie remain, as shown in the tracker: https://security-tracker.debian.org/tracker/source-package/node-lodash. Attaching the debdiff for bookworm -pu. I'll wait for your ACK before uploading the package. Let me know if you have any questions or concerns. - u
node-lodash-bookworm.debdiff
(application/octet-stream, 27.3 KB) - not displayed