Skip to content

fix: [Vuln #10] upgrade dustjs-linkedin 2.5.0 → 2.7.5 (CVE-2021-4264 - Prototype Pollution)#24

Open
devin-ai-integration[bot] wants to merge 1 commit into
mainfrom
devin/1780066177-fix-dustjs-linkedin
Open

fix: [Vuln #10] upgrade dustjs-linkedin 2.5.0 → 2.7.5 (CVE-2021-4264 - Prototype Pollution)#24
devin-ai-integration[bot] wants to merge 1 commit into
mainfrom
devin/1780066177-fix-dustjs-linkedin

Conversation

@devin-ai-integration

@devin-ai-integration devin-ai-integration Bot commented May 29, 2026

Copy link
Copy Markdown

Summary

Upgrades dustjs-linkedin from 2.5.0 to 2.7.5 to remediate CVE-2021-4264 (HIGH - Prototype Pollution). Also upgrades dustjs-helpers from 1.5.0 to 1.7.4 for compatibility (dustjs-helpers 1.7.4 supports dustjs-linkedin 2.7–2.8).

Changes:

  • dustjs-linkedin: 2.5.02.7.5
  • dustjs-helpers: 1.5.01.7.4
  • Updated package-lock.json accordingly

Review & Testing Checklist for Human

  • Verify npm ls dustjs-linkedin dustjs-helpers shows the correct versions (2.7.5 and 1.7.4)
  • Confirm Dust.js template rendering still works (check views using .dust templates)
  • Run npm install cleanly with no errors

Notes

Link to Devin session: https://app.devin.ai/sessions/1b9d10ca6a334a7d95acb6794fbfbbb0
Requested by: @jakejluo


Devin Review

Status Commit
⚪ Not started

Run Devin Review

💡 Connect your GitHub account to enable automatic code reviews.

Open in Devin Review (Staging)

… 1.7.4 (CVE-2021-4264)

Co-Authored-By: Jake Luo <jake.luo@cognition.ai>
@devin-ai-integration

Copy link
Copy Markdown
Author

🤖 Devin AI Engineer

I'll be helping with this pull request! Here's what you should know:

✅ I will automatically:

  • Address comments on this PR. Add '(aside)' to your comment to have me ignore it.
  • Look at CI failures and help fix them

Note: I can only respond to comments from users who have write access to this repository.

⚙️ Control Options:

  • Disable automatic comment, CI, and merge conflict monitoring

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant