[Git][security-tracker-team/security-tracker][master] Reserve DLA-4663-1 for node-lodash

Utkarsh Gupta (@utkarsh) utkarsh at debian.org
Wed Jul 1 23:12:46 BST 2026



Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ff6f5a86 by Utkarsh Gupta at 2026-07-02T03:42:40+05:30
Reserve DLA-4663-1 for node-lodash

- - - - -


2 changed files:

- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/DLA/list
=====================================
@@ -1,3 +1,5 @@
+[02 Jul 2026] DLA-4663-1 node-lodash - security update
+	[bullseye] - node-lodash 4.17.21+dfsg+~cs8.31.173-1+deb11u1
 [01 Jul 2026] DLA-4662-1 jq - security update
 	{CVE-2026-32316 CVE-2026-33947 CVE-2026-33948 CVE-2026-39956 CVE-2026-39979 CVE-2026-40164 CVE-2026-41256 CVE-2026-41257 CVE-2026-43894 CVE-2026-43895 CVE-2026-43896 CVE-2026-44777 CVE-2026-47770 CVE-2026-49839 CVE-2026-54679}
 	[bookworm] - jq 1.6-2.1+deb12u2


=====================================
data/dla-needed.txt
=====================================
@@ -446,16 +446,6 @@ nginx (charles)
   NOTE: 20260618: There was also a customer request to fix it. (charles)
   NOTE: 20260630: Bullseye fix release with 2 CVE fixes + http2 bomb fix. Bookworm coming soon. (charles)
 --
-node-lodash/bullseye (utkarsh)
-  NOTE: 20260131: Added by Front-Desk (Beuc)
-  NOTE: 20260201: this package is pure madness - 290 vendored sources and origtars. :)
-  NOTE: 20260201: what did i get into? d'oh. anyway, preparing unstable update first. (utkarsh)
-  NOTE: 20260201: uploaded to sid. would like for it to settle there first. (utkarsh)
-  NOTE: 20260302: no regressions reported, will start to upload to stable releases. (utkarsh)
-  NOTE: 20260623: was able to get a backport working. will run some few tests and upload this week. (utkarsh)
-  NOTE: 20260701: found a non-function regression; fix re-uploaded to debusine.d.net:
-  NOTE: 20260701: https://debusine.debian.net/debian/developers/work-request/904322/
---
 nodejs
   NOTE: 20260622: Added by Front-Desk (lamby)
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ff6f5a86b6b24db739bb4d0c98529fd807bf2425

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ff6f5a86b6b24db739bb4d0c98529fd807bf2425
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260701/91bbd420/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list