Skip to content

Conversation

@snyk-bot
Copy link
Contributor

Snyk has created this PR to upgrade underscore from 1.11.0 to 1.13.1.

merge advice
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 8 versions ahead of your current version.
  • The recommended version was released a month ago, on 2021-04-15.
Release notes
Package name: underscore
  • 1.13.1 - 2021-04-15

    Restores the underscore.js UMD alias to git

  • 1.13.0 - 2021-04-09

    Node.js native ESM support in main release stream, docs updates

  • 1.13.0-3 - 2021-03-31

    Preview release that adds the "module" exports condition

  • 1.13.0-2 - 2021-03-15

    Preview of 1.13.0 with security fix from 1.12.1

  • 1.13.0-1 - 2021-03-11

    Bugfix for the new Node.js 12+ native ESM entry point

  • 1.13.0-0 - 2021-03-10

    Node.js native ESM support (prerelease), _.debounce optimization

  • 1.12.1 - 2021-03-15

    Security fix in _.template and restored optimization in _.debounce.

  • 1.12.0 - 2020-11-24

    _.get, _.toPath, bugfixes, compatibility, performance and testing.

  • 1.11.0 - 2020-08-28

    Prepare 1.11.0

from underscore GitHub release notes

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

@snyk-bot snyk-bot requested a review from a team as a code owner May 14, 2021 20:49
@MelvinBot MelvinBot requested review from MariaHCD and removed request for a team May 14, 2021 20:49
@github-actions
Copy link
Contributor

github-actions bot commented May 14, 2021

CLA Assistant Lite bot All contributors have signed the CLA ✍️ ✅

Copy link
Contributor

@MariaHCD MariaHCD left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Following this SO: https://stackoverflow.com/c/expensify/questions/3465

I don't see any breaking changes from version 1.11.0 - 1.13.1 as per the change log. Looks like it has been mostly enhancements, bug fixes, optimizations and documentation fixes. There was a security issue in _.template but I don't believe we use this function in our repo.

Will test out the changes locally to ensure nothing breaks.

@Luke9389
Copy link
Contributor

👋 Hey, I'm making a pr that should hopefully allow snyk-bot to pass the CLA check after it gets rerun. Once my PR is merged I'll try rerunning this to see if it passes.

@MariaHCD
Copy link
Contributor

Thanks, @Luke9389! Is there anything else I should be looking out for in this version upgrade other than what I've mentioned above?

@Luke9389
Copy link
Contributor

Nope, I think your ok. Usually breaking changes constitute a new major release number, so I'm not expecting to see breaking behavior here

@MariaHCD
Copy link
Contributor

@Luke9389 Just re-ran the jobs but looks like the CLA checks are still failing 🤔

@Luke9389
Copy link
Contributor

Oh yea! I tried to get back around to all of these but must have missed this one. It seems to check out the version of master that was most recent when this PR was created. So for now, you would have to merge with failing tests (a comment will pop up that you can 👎).

Also as a reminder, we should be super careful about testing these before merging. I see that you mentioned that you would above, which is great. I'm just spreading the word that these should only be merged on an as-needed basis.

@marcaaron marcaaron closed this May 28, 2021
@marcaaron
Copy link
Contributor

I can't think of any specific reason why this dependency should be updated.

@flodnv flodnv deleted the snyk-upgrade-ff926c6c43bfc205d9007f4606e7ed07 branch February 17, 2023 19:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants