Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Vulnerability in Lodash versions below < 4.17.11 #13

Closed
sam-warren-finnair opened this issue Feb 6, 2019 · 3 comments
Closed

Vulnerability in Lodash versions below < 4.17.11 #13

sam-warren-finnair opened this issue Feb 6, 2019 · 3 comments
Labels
Bump Patch Bump patch version once released

Comments

@sam-warren-finnair
Copy link

https://snyk.io/vuln/SNYK-JS-LODASH-73639

Is it possible to up the lodash version in package.json?

@analog-nico analog-nico added the Bump Patch Bump patch version once released label Feb 14, 2019
@analog-nico
Copy link
Member

Thanks for reporting this @sam-warren-finnair ! I just released request-promise@4.2.3, request-promise-native@1.0.6, and request-promise-any@1.0.6 which bump lodash to @4.17.11.

@sam-warren-finnair
Copy link
Author

Fantastic, thanks so much for this!

@analog-nico
Copy link
Member

My pleasure buddy. :)

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
Bump Patch Bump patch version once released
Projects
None yet
Development

No branches or pull requests

2 participants