Bug#1141450: bookworm-pu: package node-lodash/4.17.21+dfsg+~cs8.31.198.20210220-9+deb12u1
Jonathan Wiltshire <[email protected]>
| Newsgroups | gmane.linux.debian.devel.release |
|---|---|
| Message-ID | <akqSRsXbthL4QjIL__45518.7955334381$1783272206$gmane$org@powdarrmonkey.net> |
Control: tag -1 wontfix Control: close -1 Hi, On Sun, Jul 05, 2026 at 04:45:35AM +0530, Utkarsh Gupta wrote: > node-lodash is affected by 3 open CVEs (CVE-2025-13465, CVE-2026-2950, > and CVE-2026-4800). This has been fixed in sid, forky, and bullseye. > Only bookworm and trixie remain, as shown in the tracker: Unfortunately this is too late now for the final point release of bookworm on 11 July 2026, unless it is critically urgent. Thanks,