Skip to content
This repository has been archived by the owner on Jan 19, 2024. It is now read-only.

Upgrade to latest lodash #7

Open
tonix-tuft opened this issue Jul 10, 2020 · 0 comments
Open

Upgrade to latest lodash #7

tonix-tuft opened this issue Jul 10, 2020 · 0 comments

Comments

@tonix-tuft
Copy link

Hi, can you update your dependencies and upgrade this package so that it uses the latest lodash@>=4.17.17?

I get a lot of security warnings from npm:

│ High          │ Prototype Pollution                                          │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package       │ lodash                                                       │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in    │ >=4.17.12                                                    │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ gulp-html-autoprefixer                                       │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path          │ gulp-html-autoprefixer > html-autoprefixer > cheerio >       │
│               │ lodash                                                       │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info     │ https://npmjs.com/advisories/1065

Thanks!

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant