Skip to content

fix: Upgrade mermaid to fix lodash-es vulnerability#11611

Merged
anthonyshew merged 1 commit intomainfrom
anthonyshew/turbo-5161-lodash-es-mermaid
Jan 31, 2026
Merged

fix: Upgrade mermaid to fix lodash-es vulnerability#11611
anthonyshew merged 1 commit intomainfrom
anthonyshew/turbo-5161-lodash-es-mermaid

Conversation

@anthonyshew
Copy link
Contributor

Summary

  • Adds lodash-es@4.17.23 as direct dependency in docs/site to fix prototype pollution vulnerability (TURBO-5161)
  • The vulnerable path was docs/site > mermaid > lodash-es which used 4.17.21
  • By adding the patched version directly, mermaid now resolves to the secure 4.17.23 version

Closes TURBO-5161

@anthonyshew anthonyshew requested a review from a team as a code owner January 31, 2026 22:07
@anthonyshew anthonyshew requested review from tknickman and removed request for a team January 31, 2026 22:07
@vercel
Copy link
Contributor

vercel bot commented Jan 31, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
examples-basic-web Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 10:08pm
examples-designsystem-docs Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 10:08pm
examples-gatsby-web Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 10:08pm
examples-kitchensink-blog Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 10:08pm
examples-nonmonorepo Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 10:08pm
examples-svelte-web Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 10:08pm
examples-tailwind-web Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 10:08pm
examples-vite-web Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 10:08pm
turbo-site Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 10:08pm
turborepo-test-coverage Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 10:08pm

@turbo-orchestrator turbo-orchestrator bot added the area: site Issues and improvements related to Turborepo's documentation website label Jan 31, 2026
@anthonyshew anthonyshew merged commit 1ed1cc5 into main Jan 31, 2026
48 checks passed
@anthonyshew anthonyshew deleted the anthonyshew/turbo-5161-lodash-es-mermaid branch January 31, 2026 22:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: site Issues and improvements related to Turborepo's documentation website

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant