lodash

lodash breaking-changes badge

lodash (latest known version: 4.18.1) has 2 known breaking changes on record, each backed by a source URL.

Actively maintainedLatest known version: 4.18.1npm ↗

Security advisories

GHSA-29mw-wpgm-hmr9MODERATE>=4.0.0 <4.17.21 || >=4.0.0 <4.17.21 || >=4.0.0 <=4.5.1 || >=4.0.0 <=4.5.1 || >=4.0.0 <4.17.21

Regular Expression Denial of Service (ReDoS) in lodash

source ↗

GHSA-35jh-r3h4-6jhmHIGH<4.17.21 || <4.17.21 || <=4.5.0 || <=1.0.0 || <4.17.21

Command Injection in lodash

source ↗

GHSA-4xc9-xhrj-v574HIGH<4.17.11 || <4.17.11

Prototype Pollution in lodash

source ↗

GHSA-f23m-r3pf-42rhMODERATE<4.18.0 || <4.18.0 || <4.18.0 || >=4.0.0 <4.18.0

lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`

source ↗

GHSA-fvqr-27wr-82fmMODERATE<4.17.5 || <4.17.5

Prototype Pollution in lodash

source ↗

GHSA-jf85-cpcp-j695CRITICAL<4.17.12 || <4.17.14 || <4.17.13 || <4.6.1 || <4.17.12

Prototype Pollution in lodash

source ↗

GHSA-p6mc-m468-83gwHIGH>=3.7.0 <4.17.19 || >=3.7.0 <4.17.20 || >=4.0.0 <=4.4.0 || >=3.7.0 <=4.3.2 || <=4.3.2 || <=4.10.2 || <=4.10.2 || >=3.7.0 <4.17.19

Prototype Pollution in lodash

source ↗

GHSA-r5fr-rjxr-66jcHIGH>=4.0.0 <4.18.0 || >=4.0.0 <4.18.0 || >=4.0.0 <4.18.0 || >=4.0.0 <4.18.0

lodash vulnerable to Code Injection via `_.template` imports key names

source ↗

GHSA-x5rq-j2xg-h7qmMODERATE>=4.7.0 <4.17.11 || >=4.7.0 <4.17.11 || >=4.7.0 <4.17.11 || >=4.7.0 <4.17.11

Regular Expression Denial of Service (ReDoS) in lodash

source ↗

GHSA-xxjr-mmjv-4gpgMODERATE>=4.0.0 <4.17.23 || >=4.0.0 <=4.5.2 || >=4.0.0 <4.17.23 || >=4.0.0 <4.17.23

Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions

source ↗

Recent changes

v4.0.0Breaking

We’ve introduced more breaking changes in this release than any other so be sure to check out the [changelog](https://github.com/lodash/lodash/wiki/Changelog#compatibility-warnings) for a full rundown of changes & give [lodash-migrate](https://www.npmjs.com/package/lodash-migrate) a spin to help migrate older Lodash code to the latest release. If you dig Lodash don’t forget to [star the repo](https://github.com/lodash/lodash/stargazers) or `npm star lodash`!

source ↗

v3.0.0Breaking

lodash v3 is a major bump & we’ve introduced several back-compat breaking changes. One such change is that while we still [test against](https://saucelabs.com/u/lodash) Underscore/Backbone unit tests we’re no longer supporting an Underscore/Backbone build. Over the last year we’ve seen Underscore align more & more with lodash’s API so the need for a separate Underscore build has diminished. If you still need compatibility around some of the edges we recommend leveraging modules in lodash v3 to supplement your Underscore use. Be sure to check out the [changelog](https://github.com/lodash/lodash/wiki/Changelog#compatibility-warnings-1) for a full rundown of changes & give [lodash-migrate](https://www.npmjs.com/package/lodash-migrate) a spin to help migrate older lodash code to the latest release.

source ↗

Check what changed for lodash since your installed version, live.

Open the playground →