Use Lodash's _.template
instead of lodash.template
package
#10458
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
edit: Resolves #10459.
CVE-2021-23337 was recently updated to reflect an issue previously patched in Lodash also being present in the
lodash.template
package, which from all appearances is no longer maintained. I should emphasize there's nothing I've seen to suggest there's any significant risk in terms of how ember-cli uses this package currently, but it still raises alerts on NPM/GitHub that would be best to clear if possible.This PR replaces
lodash.template
with the overalllodash
package – which is already a transitive dependency – and substitutes it in the two places where it was being used. I ran the existing tests for these two modules and they passed.Note that this does not yet fully removelodash.template
from the dependency tree; it is also a dependency ofbroccoli-concat
viasourcemap-validator
(v1.1.1) which I intend to raise separately shortly.Edit: On further review I noticed that the current versioning would accept bumping
fast-sourcemap-concat
to v2.1.1 and that doing so would remove thelodash.template
dependency entirely.If anything else is needed to ensure this can be back-merged to the LTS versions, please let me know.