Conversation
🦋 Changeset detectedLatest commit: f2d9cef The changes in this PR will be included in the next version bump. This PR includes changesets to release 4 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
PR SummaryMedium Risk Overview Adjusts TypeScript imports/usages to match the upgraded libraries: moves Written by Cursor Bugbot for commit f2d9cef. This will update automatically on new commits. Configure here. |
There was a problem hiding this comment.
CVE-2025-13465 in lodash - medium severity
Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes.
The issue permits deletion of properties but does not allow overwriting their original behavior.
This issue is patched on 4.17.23
Remediation Aikido suggests bumping this package to version 4.17.23 to resolve this issue
View details in Aikido Security
Codecov Report✅ All modified and coverable lines are covered by tests.
🚀 New features to boost your workflow:
|
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
Bugbot Autofix is OFF. To automatically fix reported issues with Cloud Agents, enable Autofix in the Cursor dashboard.
PR-Codex overview
This PR focuses on updating dependencies and making minor adjustments in type definitions across various packages in the project.
Detailed summary
BaseError,Address, andChaintypes inprepareTransaction.ts,linkToAgw.ts, anduseGlobalWalletSignerClient.ts.package.jsonfiles.typescriptandviemversions across multiple packages.@privy-io/cross-app-connectversion to0.5.2.addressinuseGlobalWalletSignerClient.