From c3b9b27368b405ed9574245e6f43bce3100c556b Mon Sep 17 00:00:00 2001
From: Ivan Sekovanikj <31964049+isekovanic@users.noreply.github.com>
Date: Tue, 3 Feb 2026 13:40:04 +0100
Subject: [PATCH] fix: bump vulnerable lodash and linkify versions (#3383)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
## ๐ฏ Goal
## ๐ Implementation details
## ๐จ UI Changes
iOS
Android
## ๐งช Testing
## โ๏ธ Checklist
- [ ] I have signed the [Stream
CLA](https://docs.google.com/forms/d/e/1FAIpQLScFKsKkAJI7mhCr7K9rEIOpqIDThrWxuvxnwUq2XkHyG154vQ/viewform)
(required)
- [ ] PR targets the `develop` branch
- [ ] Documentation is updated
- [ ] New code is tested in main example apps, including all possible
scenarios
- [ ] SampleApp iOS and Android
- [ ] Expo iOS and Android
---
package/package.json | 4 ++--
package/yarn.lock | 13 ++++---------
2 files changed, 6 insertions(+), 11 deletions(-)
diff --git a/package/package.json b/package/package.json
index 32d4266af..494709b40 100644
--- a/package/package.json
+++ b/package/package.json
@@ -74,8 +74,8 @@
"emoji-regex": "^10.4.0",
"i18next": "^25.2.1",
"intl-pluralrules": "^2.0.1",
- "linkifyjs": "^4.3.1",
- "lodash-es": "4.17.21",
+ "linkifyjs": "^4.3.2",
+ "lodash-es": "4.17.23",
"mime-types": "^2.1.35",
"path": "0.12.7",
"react-native-markdown-package": "1.8.2",
diff --git a/package/yarn.lock b/package/yarn.lock
index b4a490461..24a3abe7e 100644
--- a/package/yarn.lock
+++ b/package/yarn.lock
@@ -6320,11 +6320,6 @@ lines-and-columns@^1.1.6:
resolved "https://registry.yarnpkg.com/lines-and-columns/-/lines-and-columns-1.2.4.tgz#eca284f75d2965079309dc0ad9255abb2ebc1632"
integrity sha512-7ylylesZQ/PV29jhEDl3Ufjo6ZX7gCqJr5F7PKrqc93v7fzSymt1BpwEU8nAUXs8qzzvqhbjhK5QZg6Mt/HkBg==
-linkifyjs@^4.3.1:
- version "4.3.1"
- resolved "https://registry.yarnpkg.com/linkifyjs/-/linkifyjs-4.3.1.tgz#1f246ebf4be040002accd1f4535b6af7c7e37898"
- integrity sha512-DRSlB9DKVW04c4SUdGvKK5FR6be45lTU9M76JnngqPeeGDqPwYc0zdUErtsNVMtxPXgUWV4HbXbnC4sNyBxkYg==
-
linkifyjs@^4.3.2:
version "4.3.2"
resolved "https://registry.yarnpkg.com/linkifyjs/-/linkifyjs-4.3.2.tgz#d97eb45419aabf97ceb4b05a7adeb7b8c8ade2b1"
@@ -6352,10 +6347,10 @@ locate-path@^6.0.0:
dependencies:
p-locate "^5.0.0"
-lodash-es@4.17.21:
- version "4.17.21"
- resolved "https://registry.yarnpkg.com/lodash-es/-/lodash-es-4.17.21.tgz#43e626c46e6591b7750beb2b50117390c609e3ee"
- integrity sha512-mKnC+QJ9pWVzv+C4/U3rRsHapFfHvQFoFB92e52xeyGMcX6/OlIl78je1u8vePzYZSkkogMPJ2yjxxsb89cxyw==
+lodash-es@4.17.23:
+ version "4.17.23"
+ resolved "https://registry.yarnpkg.com/lodash-es/-/lodash-es-4.17.23.tgz#58c4360fd1b5d33afc6c0bbd3d1149349b1138e0"
+ integrity sha512-kVI48u3PZr38HdYz98UmfPnXl2DXrpdctLrFLCd3kOx1xUkOmpFPx7gCWWM5MPkL/fD8zb+Ph0QzjGFs4+hHWg==
lodash.debounce@^4.0.8:
version "4.0.8"