Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

lodash vulnerability #32

Open
hassaans opened this issue Jan 13, 2019 · 3 comments
Open

lodash vulnerability #32

hassaans opened this issue Jan 13, 2019 · 3 comments
Labels
enhancement good first issue New contributors welcome!

Comments

@hassaans
Copy link

hassaans commented Jan 13, 2019

npm audit shows "Prototype Pollution" vulnerability.

screen shot 2019-01-14 at 12 32 30 am

@thescientist13
Copy link
Collaborator

Thanks @hassaans !

Would you be up for opening a PR to update our dependencies and fix these suggestions?

@joshuaavalon
Copy link

I faced the same problem. It probably needs to update critical to 2.0.0. However, critical is in beta and has breaking changes.

@rickvandermey
Copy link

The problem is in deeper dependency package cheerio. Currently running 0.22.0 and documentation states they are working on 1.0.0. Hope to see lodash updated there, in an hotfix.

@thescientist13 thescientist13 added help wanted good first issue New contributors welcome! and removed help wanted labels Jan 29, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement good first issue New contributors welcome!
Projects
None yet
Development

No branches or pull requests

4 participants