• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

jfcere / ngx-markdown / 44a1a4e3-daa6-4d8e-aeae-43961db880ed
97%
master: 97%

Build:
Build:
LAST BUILD BRANCH: fix/lodash-vulnerability
DEFAULT BRANCH: master
Ran 02 Apr 2026 05:07PM UTC
Jobs 1
Files 13
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

02 Apr 2026 05:06PM UTC coverage: 96.759% (-0.2%) from 96.991%
44a1a4e3-daa6-4d8e-aeae-43961db880ed

Pull #636

circleci

Marcusg62
fix: override lodash and lodash-es to >=4.18.0 to resolve CVEs

Add npm overrides for lodash and lodash-es to force >=4.18.0 across
all transitive dependencies. This resolves two high-severity
vulnerabilities in lodash <=4.17.23:

- GHSA-r5fr-rjxr-66jc (Code Injection via _.template imports)
- GHSA-f23m-r3pf-42rh (Prototype Pollution via _.unset and _.omit)

The vulnerable lodash versions are transitive dependencies brought in
by karma (lodash) and mermaid/chevrotain (lodash-es). Upstream fixes
are pending (karma-runner/karma#3931, Chevrotain/chevrotain#2184),
so overrides are the practical fix for now.

Closes #635
Pull Request #636: fix: override lodash to >=4.18.0 to resolve CVEs

110 of 119 branches covered (92.44%)

Branch coverage included in aggregate %.

308 of 313 relevant lines covered (98.4%)

24.65 hits per line

Jobs
ID Job ID Ran Files Coverage
1 44a1a4e3-daa6-4d8e-aeae-43961db880ed.1 02 Apr 2026 05:07PM UTC 13
96.76
Source Files on build 44a1a4e3-daa6-4d8e-aeae-43961db880ed
  • Tree
  • List 13
  • Changed 1
  • Source Changed 0
  • Coverage Changed 1
Coverage ∆ File Lines Relevant Covered Missed Hits/Line Branch Hits Branch Misses
  • Back to Repo
  • CircleCI Build #44A1A4E3...
  • Pull Request #636
  • PR Base - master (#00E8419B...)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc