-
Notifications
You must be signed in to change notification settings - Fork 44
Closed
Description
Note: This feels somewhat lower priority because the vulnerable methods in question aren't used, but resolving this can can fix package installation/audit warnings and prevent accidental usage of vulnerable methods:
Similar to #13, lodash requires another upgrade due to a reported vulnerability in the version used in this repo:
- Per https://github.com/lodash/lodash/issues/4348, an upgrade is required to address a recent security vulnerability CVE-2019-10744
- https://github.com/request/promise-core/blob/master/package.json#L36 lists the vulnerable lodash version
LRNZ09, shikya and sepehr
Metadata
Metadata
Assignees
Labels
No labels