gulp-header
gulp-header copied to clipboard
Command Injection in lodash
Transitive dependency lodash.template 4.5.0 is introduced via gulp-header 2.0.9 lodash.template 4.5.0
I see there are 3 pull requests which seem to fix the issue, can one of them be merged?
https://github.com/gulp-community/gulp-header/pull/70 was merged which fixes this, but it has not been released yet