Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
openQA only uses lodash via dagre(-d3), and AFAICS, the versions of dagre(-d3) used by openQA never uss the affected options.imports feature: [adamw@toolbx fedora-toolbox-43 dagre ((v0.8.5))]$ grep -R imports [adamw@toolbx fedora-toolbox-43 dagre ((v0.8.5))]$ [adamw@toolbx fedora-toolbox-43 dagre-d3 ((v0.6.4))]$ grep -R imports [adamw@toolbx fedora-toolbox-43 dagre-d3 ((v0.6.4))]$ so I don't think this is a practical issue for openQA. I'll still see if we can update lodash upstream.