Skip to content

Bump mongoose from 9.6.3 to 9.9.0 - #368

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/mongoose-9.9.0
Closed

Bump mongoose from 9.6.3 to 9.9.0#368
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/mongoose-9.9.0

Bump mongoose from 9.6.3 to 9.9.0

79da085
Select commit
Loading
Failed to load commit list.
Codacy Production / Codacy Static Code Analysis required action Aug 3, 2026 in 0s

3 new security issues (0 max.).

Codacy Here is an overview of what got changed by this pull request:

Issues
======
- Added 3
           

See the complete overview on Codacy

Annotations

Check warning on line 22 in pnpm-lock.yaml

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

pnpm-lock.yaml#L22

Insecure dependency npm/lodash@4.17.21 (CVE-2025-13465: lodash: prototype pollution in _.unset and _.omit functions) (update to 4.17.23)

Check warning on line 22 in pnpm-lock.yaml

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

pnpm-lock.yaml#L22

Insecure dependency npm/lodash@4.17.21 (CVE-2026-2950: lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass) (update to 4.18.0)

Check warning on line 22 in pnpm-lock.yaml

See this annotation in the file changed.

@codacy-production codacy-production / Codacy Static Code Analysis

pnpm-lock.yaml#L22

Insecure dependency npm/lodash@4.17.21 (CVE-2026-4800: lodash: lodash: Arbitrary code execution via untrusted input in template imports) (update to 4.18.0)