From 2cc6bb5a828e99183fb31eda97507f91ba6de16c Mon Sep 17 00:00:00 2001 From: prabhakar Date: Fri, 24 Apr 2026 13:38:45 +0530 Subject: [PATCH] OCPBUGS-79441: immutable bump Bump immutable from 3.8.2 to 3.8.3 to address prototype pollution vulnerability via mergeDeep, merge, toJS, toObject (CVE-2026-29063). --- package-lock.json | 2 +- package.json | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/package-lock.json b/package-lock.json index 54c5264f..eab0796d 100644 --- a/package-lock.json +++ b/package-lock.json @@ -30,7 +30,7 @@ "i18next": "^21.8.14", "i18next-http-backend": "^2.2.0", "i18next-parser": "^8.11.0", - "immutable": "3.x", + "immutable": "^3.8.3", "lodash-es": "^4.17.21", "murmurhash-js": "1.0.x", "react": "^17.0.1", diff --git a/package.json b/package.json index 949d1dc7..8baa9bbf 100644 --- a/package.json +++ b/package.json @@ -46,7 +46,7 @@ "i18next": "^21.8.14", "i18next-http-backend": "^2.2.0", "i18next-parser": "^8.11.0", - "immutable": "3.x", + "immutable": "^3.8.3", "lodash-es": "^4.17.21", "murmurhash-js": "1.0.x", "react": "^17.0.1",