From 76ae81fbaa8ceb3404408277c45f6e5ac0aef2cd Mon Sep 17 00:00:00 2001 From: Philip Theobald Date: Mon, 31 Jan 2022 13:22:28 -0600 Subject: [PATCH 1/2] Fix CVE-2019-10744 Update LoDash sub-dependency to address https://nvd.nist.gov/vuln/detail/CVE-2019-10744 --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index ed0e666..b81e9a0 100644 --- a/package.json +++ b/package.json @@ -44,7 +44,7 @@ ], "dependencies": { "glob": "~7.1.1", - "lodash": "~4.17.10", + "lodash": "~4.17.21", "minimatch": "~3.0.2" } } From 82d78a498b4e916d843dcc0cf64245497f63c505 Mon Sep 17 00:00:00 2001 From: Philip Theobald Date: Mon, 31 Jan 2022 13:29:05 -0600 Subject: [PATCH 2/2] Update package.json Auto update to minor version --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index b81e9a0..e2f7af0 100644 --- a/package.json +++ b/package.json @@ -44,7 +44,7 @@ ], "dependencies": { "glob": "~7.1.1", - "lodash": "~4.17.21", + "lodash": "^4.17.21", "minimatch": "~3.0.2" } }