This repository was archived by the owner on Oct 1, 2020. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 22
update lodash to v4.17.20 #104
Labels
Comments
PR: #105 |
1 task
@jennifer-shehane - would you consider switching to using caret syntax for dependencies ( |
Yes, we did this for our main Cypress project already. |
@berickson1 PR here #107 |
🎉 This issue has been resolved in version 5.4.5 🎉 The release is available on:
Your semantic-release bot 📦🚀 |
# for free
to subscribe to this conversation on GitHub.
Already have an account?
#.
Is this a Feature or Bug?
Bug, lodash 4.17.19 is vulnerable to Prototype pollution according to snyk: https://app.snyk.io/vuln/SNYK-JS-LODASH-590103
Current behavior:
Desired behavior:
Update package to lodash 4.17.20
How to reproduce:
Additional Info (images, stack traces, etc)
The text was updated successfully, but these errors were encountered: