Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Old version of lodash in dependency have known vulnerabilities #264

Open
EBendinelli opened this issue Jun 4, 2021 · 1 comment
Open

Comments

@EBendinelli
Copy link

Hi there,

I was just checking Google's new project Insight (https://deps.dev/) and happened to check a tool I'm using (mastodon-bot). This package was flagged with a vulnerability and it took me down a rabbit hole of dependancies ending more or less here: https://deps.dev/npm/gulp-eslint/3.0.1

Gulp-eslint seems to be loading a few packages with lodash dependency, some of those are old version with a known vulnerability (<4.17.21). I've checked the package-lock.json and it seems @shinnn/eslint-config might be the culprit as version 5.0.0 is currently loaded (version 7.0.0 is available).

Bear in mind I might have misread all that but if not you might want to update this dependency.

@doamatto
Copy link

This should be fixed in my fork here, as I don't believe this is being maintained anymore.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants