Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

[api-extractor] Consider using caret (^) instead of tilde (~) for lodash dependency

Đang mở
#5,742 1 bình luận 5 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
3/5
Thời gian dự kiến
Nửa ngày
Mức phù hợp với người mới
48/100
Loại issue
Tái cấu trúc
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Ít trao đổi
Công nghệ
nodejs, typescript
Lĩnh vực
build-system, tooling

Hướng nghiên cứu

Start by locating the api-extractor package.json and reviewing its lodash and other tilde-pinned dependency entries. Regenerate the relevant lockfiles or dependency resolution, then verify that the intended minor versions resolve without breaking api-extractor; done means the agreed dependency ranges are updated and security fixes can be received without an api-extractor release.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

Summary

The lodash dependency is pinned using a tilde range (~4.17.23), which only permits patch updates within the 4.17.x line. Lodash 4.18.0 was recently released to address CVE-2026-4800, a code injection vulnerability in the _.template function. Because of the tilde constraint, consumers of api-extractor cannot receive this security fix without an explicit update to the package.json in this repository.

More broadly, several other dependencies in api-extractor also use tilde ranges (e.g., @microsoft/tsdoc, resolve, semver, source-map). Switching these to caret ranges would allow consumers to benefit from minor version updates - including security patches - without requiring a new api-extractor release.

Repro steps

Expected result: Consumers can receive lodash security patches (e.g., 4.18.0) when regenerating their lockfiles.

Actual result: The ~4.17.23 constraint prevents resolution to 4.18.0, leaving consumers exposed to CVE-2026-4800 until api-extractor explicitly updates its dependency.

Details

Suggested change:

  • "lodash": "~4.17.23"
  • "lodash": "^4.17.23"

Broader suggestion: Consider updating all tilde-pinned dependencies to use caret ranges, allowing minor version updates that could include security patches.

Using a caret range would allow minor version updates (4.17.x → 4.18.x), enabling consumers to automatically receive security patches that are published in minor releases.

References:

Standard questions

Question Answer
@microsoft/api-extractor version? 7.57.8
Operating system? Mac
API Extractor scenario? rollups (.d.ts)
Would you consider contributing a PR? Yes
TypeScript compiler version? 5.5.4
Node.js version (node -v)? 24.14.0
Ngôn ngữ chính
TypeScript
Star
6.5k
Fork
708
Merge trung bình
5 ngày 19 giờ
Pull request đã merge (30 ngày)
48

Hướng dẫn đóng góp

Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của microsoft/rushstack

Tất cả issue của microsoft/rushstack

Issue tương tự

Thêm issue về TypeScript

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.