Skip to content

chore: bump lodash from 4.17.21 to 4.18.1 in /RNExample - #697

Merged
jamesnrokt merged 1 commit into
mainfrom
dependabot/npm_and_yarn/RNExample/lodash-4.18.1
Sep 1, 2026
Merged

chore: bump lodash from 4.17.21 to 4.18.1 in /RNExample#697
jamesnrokt merged 1 commit into
mainfrom
dependabot/npm_and_yarn/RNExample/lodash-4.18.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Apr 2, 2026

Copy link
Copy Markdown
Contributor

Bumps lodash from 4.17.21 to 4.18.1.

Release notes

Sourced from lodash's releases.

4.18.1

Bugs

Fixes a ReferenceError issue in lodash lodash-es lodash-amd and lodash.template when using the template and fromPairs functions from the modular builds. See lodash/lodash#6167

These defects were related to how lodash distributions are built from the main branch using https://github.com/lodash-archive/lodash-cli. When internal dependencies change inside lodash functions, equivalent updates need to be made to a mapping in the lodash-cli. (hey, it was ahead of its time once upon a time!). We know this, but we missed it in the last release. It's the kind of thing that passes in CI, but fails bc the build is not the same thing you tested.

There is no diff on main for this, but you can see the diffs for each of the npm packages on their respective branches:

4.18.0

v4.18.0

Full Changelog: lodash/lodash@4.17.23...4.18.0

Security

_.unset / _.omit: Fixed prototype pollution via constructor/prototype path traversal (GHSA-f23m-r3pf-42rh, fe8d32e). Previously, array-wrapped path segments and primitive roots could bypass the existing guards, allowing deletion of properties from built-in prototypes. Now constructor and prototype are blocked unconditionally as non-terminal path keys, matching baseSet. Calls that previously returned true and deleted the property now return false and leave the target untouched.

_.template: Fixed code injection via imports keys (GHSA-r5fr-rjxr-66jc, CVE-2026-4800, 879aaa9). Fixes an incomplete patch for CVE-2021-23337. The variable option was validated against reForbiddenIdentifierChars but importsKeys was left unguarded, allowing code injection via the same Function() constructor sink. imports keys containing forbidden identifier characters now throw "Invalid imports option passed into _.template".

Docs

  • Add security notice for _.template in threat model and API docs (#6099)
  • Document lower > upper behavior in _.random (#6115)
  • Fix quotes in _.compact jsdoc (#6090)

lodash.* modular packages

Diff

We have also regenerated and published a select number of the lodash.* modular packages.

These modular packages had fallen out of sync significantly from the minor/patch updates to lodash. Specifically, we have brought the following packages up to parity w/ the latest lodash release because they have had CVEs on them in the past:

Commits
  • cb0b9b9 release(patch): bump main to 4.18.1 (#6177)
  • 75535f5 chore: prune stale advisory refs (#6170)
  • 62e91bc docs: remove n_ Node.js < 6 REPL note from README (#6165)
  • 59be2de release(minor): bump to 4.18.0 (#6161)
  • af63457 fix: broken tests for _.template 879aaa9
  • 1073a76 fix: linting issues
  • 879aaa9 fix: validate imports keys in _.template
  • fe8d32e fix: block prototype pollution in baseUnset via constructor/prototype traversal
  • 18ba0a3 refactor(fromPairs): use baseAssignValue for consistent assignment (#6153)
  • b819080 ci: add dist sync validation workflow (#6137)
  • Additional commits viewable in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [lodash](https://github.com/lodash/lodash) from 4.17.21 to 4.18.1.
- [Release notes](https://github.com/lodash/lodash/releases)
- [Commits](lodash/lodash@4.17.21...4.18.1)

---
updated-dependencies:
- dependency-name: lodash
  dependency-version: 4.18.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Apr 2, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner April 2, 2026 09:44
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Apr 2, 2026
@cursor

cursor Bot commented Apr 2, 2026

Copy link
Copy Markdown

PR Summary

Low Risk
Lockfile-only dependency bump with no application code changes; risk is limited to potential upstream behavior changes in tooling/tests that transitively use lodash.

Overview
Updates the RNExample app’s npm lockfile to bump the lodash dev dependency from 4.17.21 to 4.18.1 (updating the tarball URL and integrity hash accordingly).

Written by Cursor Bugbot for commit 06a6c82. This will update automatically on new commits. Configure here.

@github-actions

github-actions Bot commented Apr 2, 2026

Copy link
Copy Markdown

📦 SDK Size Impact Report

Measures how much the SDK adds to an app's size (with-SDK minus without-SDK).

Metric Target Branch This PR Change
App Bundle Impact 1.82 MB 1.82 MB +N/A
Executable Impact 896 bytes 896 bytes +N/A
XCFramework Size 9.51 MB 9.50 MB -4 KB

➡️ SDK size impact change is minimal.

Raw measurements

Target branch (main):

{"baseline_app_size_kb":84,"baseline_executable_size_bytes":75464,"with_sdk_app_size_kb":1948,"with_sdk_executable_size_bytes":76360,"sdk_impact_kb":1864,"sdk_executable_impact_bytes":896,"xcframework_size_kb":9736}

This PR:

{"baseline_app_size_kb":84,"baseline_executable_size_bytes":75464,"with_sdk_app_size_kb":1948,"with_sdk_executable_size_bytes":76360,"sdk_impact_kb":1864,"sdk_executable_impact_bytes":896,"xcframework_size_kb":9732}

@jamesnrokt
jamesnrokt merged commit f17c3f2 into main Sep 1, 2026
15 of 16 checks passed
@jamesnrokt
jamesnrokt deleted the dependabot/npm_and_yarn/RNExample/lodash-4.18.1 branch September 1, 2026 15:45
nickolas-dimitrakas added a commit that referenced this pull request Sep 2, 2026
…st fixes (#915)

* feat: accept native GoDaddy R1 certificate chains (#879)

feat(network): accept native GoDaddy R1 certificate chains

Add GoDaddy TLS Root CA - R1 to the default certificate set while retaining all existing trust anchors.

Verify the embedded certificate against GoDaddy's published SHA-256 fingerprint to prevent accidental pin changes.

#agentic

* chore: Release v9.4.1 (#881)

chore: (release) 9.4.1

Updates version to 9.4.1 across the mParticle ecosystem.

* docs: trim AGENTS.md to the non-derivable core

* docs: correct the disabled-workflow and fork-PR notes

* docs: state the Xcode-pin split without pinning versions in prose

* docs: correct the disabled-workflow gotcha in AGENTS.md

release-ecosystem-from-main.yml is registered in Actions as
disabled_manually but its file is not on main at all - only on unmerged
branches - so describing it as a workflow file in the tree that never
runs was wrong. The real trap is that the workflow list and the tree
disagree in both directions.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* docs: record how to place a red or cancelled check

Observed on this branch: the build-kits Pod Lint jobs fail as a batch on
a CocoaPods CDN error, and a cancelled job is a timeout-minutes expiry or
a superseded push under pull-request.yml's cancel-in-progress concurrency
group - not a test result.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* chore: add CODEOWNERS to mirrored kit subtrees (#885)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* chore: bump actions/setup-java from 5 to 6 (#886)

Bumps [actions/setup-java](https://github.com/actions/setup-java) from 5 to 6.
- [Release notes](https://github.com/actions/setup-java/releases)
- [Commits](actions/setup-java@v5...v6)

---
updated-dependencies:
- dependency-name: actions/setup-java
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* ci: stop simulator cloning and bound network/test hangs (#867)

* ci: stop simulator cloning and bound network/test hangs

Two unrelated hangs were holding up CI. Both were unbounded, so they
consumed a job's full budget instead of failing.

native-tests: the iOS x mParticle-Apple-SDK-Swift cell repeatedly hit its
15-minute timeout. A single test, MPDeviceTests.testDictionaryDescription,
took 156-459s across recent runs while every other test finished in under
1.6s; job duration tracked that test exactly. The same test takes 0.069s on
tvOS in the same run, so the cause is simulator state, not the assertions.
MPDevice reads UIDevice.current for name and identifierForVendor, which are
XPC calls into simulator daemons, and mParticle-Apple-SDK-Swift.xcscheme is
the only scheme in the repo with parallelizable="YES" - so xcodebuild clones
and boots extra iOS simulators on a runner that just erased one, starving the
daemons that test then blocks on.

Disable parallel testing for the run. The suite is ~2s of tests; locally
this is 2x faster end to end (33s vs 74s) because it no longer boots 8
simulator clones. Also wait for a real boot via simctl bootstatus - the
action's wait_for_boot only waits for state=Booted, not for first-boot work
to finish - and add a per-test timeout so a hung test fails in 2 minutes
with an explicit diagnostic instead of silently eating the job timeout. The
slowest genuine test on CI is ~30s, leaving 4x headroom.

build-kits: Build rokt-sdk-plus-ios stalled 30 minutes inside a git fetch of
stripe-ios (2.7 GB, reached transitively via rokt-payment-extension-ios),
leaving orphaned git and git-remote-http processes. The job has no
timeout-minutes, so only an unrelated concurrency cancel stopped it;
otherwise it would have held a macOS runner for the 6-hour default.

Make git abort a transfer stalled below 1 KB/s for 3 minutes, retry the
resolve three times (matching the existing pod-lint-kits pattern), and add
job timeouts so no hang here can run unbounded again. Healthy resolves take
2-5 minutes.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* ci: bound each SPM resolve attempt with a kill-and-retry watchdog

The first version of this fix relied on git's own low-speed abort to break
a stalled fetch. It does not fire: on run 33010942238 the stripe-ios fetch
sat for 24.5 minutes with http.lowSpeedLimit/lowSpeedTime set, produced no
error, and never returned - so the retry loop never got a turn and the step
burned its whole 25-minute budget before failing.

Bound each attempt explicitly instead. A watchdog kills the resolve and its
surviving git children once an attempt passes ATTEMPT_TIMEOUT_SECONDS (480s,
against a healthy 2-5 minute resolve), so a stalled attempt is retried rather
than consuming the step. Drop to 2 attempts and a 20-minute step timeout,
since an attempt can no longer run unbounded.

Keep the git low-speed config: it is not sufficient on its own but still
aborts genuinely slow transfers where it does apply.

Verified against the extracted step body with a stubbed resolver: a healthy
resolve exits 0 in 1s with no kills; a permanent hang is killed twice and
fails bounded; a hang followed by a healthy retry is killed once and exits 0.
Defaulted the timeout in-place so an unset variable cannot make the watchdog
fire immediately.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* ci: run the resolve watchdog cleanup in the parent so it actually executes

Bugbot caught that the watchdog's cleanup was dead code. The watchdog TERMed
the resolve subshell and then slept 5s before escalating, but TERMing the
resolve unblocks the parent's wait immediately, and the parent then kills the
watchdog mid-sleep - so the kill -KILL and the pkill of leftover xcodebuild
and git-remote-http children never ran. The retry could therefore start while
the previous stalled fetch was still alive and race it over SwiftPM's cache
locks, which is the exact failure the watchdog was added to prevent.

The watchdog now only records that it fired (via a marker file) and sends
TERM. Escalation and child cleanup run in the parent after wait returns, where
they cannot be pre-empted, followed by a short grace period before the retry.

Verified by extracting the step body, stubbing the resolver and replacing the
pkill calls with probes: on the old code the cleanup probes fired 0 times out
of 4 expected; they now fire 4/4 on a permanent hang and 2/2 when one attempt
hangs and the retry succeeds. Cleanup still does not run on a non-timeout
failure (0 probes), so a fast failure does not trigger a spurious pkill, and
the healthy path is unchanged at exit 0 with no kills.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* test: make workspace-switch and kit-registry concurrency tests deterministic (#870)

testSwitchWorkspaceKitsWithStop waited on two nested 10-second dispatch_after
blocks, so it always burned at least 20 seconds of wall clock and depended on
fixed timing rather than on the SDK actually being ready. Wait on the SDK's own
readiness signals instead - MParticle.initialized after startWithOptions:, and
the replacement shared instance after switchWorkspaceWithOptions: - by spinning
the main run loop until the condition holds. The assertions are unchanged, so
the test still checks the same behaviour; it now takes 0.11s instead of 20.2s.

testActiveKitsRegistryThreadSafety tracked failure in a plain __block BOOL
written from four concurrent blocks, which is itself an unsynchronized data
race, and called XCTFail from those background queues. Guard the shared state
with an NSLock, record only the first exception, and report it from the
dispatch_group_notify block on the main queue.

This commit does not change the flakiness of testActiveKitsRegistryThreadSafety
itself: that crash is a real race in MPKitContainer (flushSerializedKits
enumerates and mutates kitsRegistry without kitsSemaphore, reached via the
early return in configureKits: before the lock is taken). Reproduced at 2
crashes in 10 runs of that test alone. Fixing it changes core SDK locking, so
it is deliberately left for a separate, explicitly-reviewed change.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* chore: bump minimatch from 3.1.2 to 3.1.5 in /RNExample (#640)

Bumps [minimatch](https://github.com/isaacs/minimatch) from 3.1.2 to 3.1.5.
- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md)
- [Commits](isaacs/minimatch@v3.1.2...v3.1.5)

---
updated-dependencies:
- dependency-name: minimatch
  dependency-version: 3.1.5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore: bump lodash from 4.17.21 to 4.18.1 in /RNExample (#697)

Bumps [lodash](https://github.com/lodash/lodash) from 4.17.21 to 4.18.1.
- [Release notes](https://github.com/lodash/lodash/releases)
- [Commits](lodash/lodash@4.17.21...4.18.1)

---
updated-dependencies:
- dependency-name: lodash
  dependency-version: 4.18.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore: bump @babel/plugin-transform-modules-systemjs from 7.25.9 to 7.29.4 in /RNExample (#767)

chore: bump @babel/plugin-transform-modules-systemjs in /RNExample

Bumps [@babel/plugin-transform-modules-systemjs](https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-transform-modules-systemjs) from 7.25.9 to 7.29.4.
- [Release notes](https://github.com/babel/babel/releases)
- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md)
- [Commits](https://github.com/babel/babel/commits/v7.29.4/packages/babel-plugin-transform-modules-systemjs)

---
updated-dependencies:
- dependency-name: "@babel/plugin-transform-modules-systemjs"
  dependency-version: 7.29.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore: bump shell-quote from 1.8.1 to 1.10.0 in /RNExample (#799)

Bumps [shell-quote](https://github.com/ljharb/shell-quote) from 1.8.1 to 1.10.0.
- [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md)
- [Commits](ljharb/shell-quote@v1.8.1...v1.10.0)

---
updated-dependencies:
- dependency-name: shell-quote
  dependency-version: 1.10.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix: stop the partial mock before releasing the object it wraps

MPRoktTests.m diverged too far from main's version for the preceding merge to
carry this over as part of it - main's tearDown reorders the same two lines,
but the files no longer share enough context for a line-based merge to find
that hunk. Applying it directly here instead: releasing self.rokt while
OCMPartialMock(self.rokt) is still installed is the wrong order regardless of
which branch's file structure it's in.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: Thomson Thomas <125323226+thomson-t@users.noreply.github.com>
Co-authored-by: mParticle Bot User <developers@mparticle.com>
Co-authored-by: Matt Bodle <matt.bodle@rokt.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: James Newman <james.newman@rokt.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Matt Bodle <22z33p@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant