Bug#1141450: bookworm-pu: package node-lodash/4.17.21+dfsg+~cs8.31.198.20210220-9+deb12u1

Jonathan Wiltshire <[email protected]>
Newsgroups gmane.linux.debian.devel.release
Message-ID <akqSRsXbthL4QjIL__45518.7955334381$1783272206$gmane$org@powdarrmonkey.net>
Control: tag -1 wontfix
Control: close -1

Hi,

On Sun, Jul 05, 2026 at 04:45:35AM +0530, Utkarsh Gupta wrote:
> node-lodash is affected by 3 open CVEs (CVE-2025-13465, CVE-2026-2950,
> and CVE-2026-4800). This has been fixed in sid, forky, and bullseye.
> Only bookworm and trixie remain, as shown in the tracker:

Unfortunately this is too late now for the final point
release of bookworm on 11 July 2026, unless it is critically urgent.

Thanks,
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.