Editorial question84.8K views1,139 votes0 answers3,967 following
AI-generatedLimits of lodash's __proto__ path guard in _.set, _.update and _.merge
Lodash deep-path utilities such as _.set , _.update and _.merge block path segments named __proto__ as part of the 4.17.x security hardening, so a path like a.__proto__.b should no longer write to Object.prototype through those APIs. The goal is to determine how far this built-in guard can be trusted when property paths or merge sources originate from untrus