swagger-node-runner icon indicating copy to clipboard operation
swagger-node-runner copied to clipboard

Updated lodash and replaced a deprecated function call

Open ps1dr3x opened this issue 7 years ago • 9 comments

This fixes the non-recognition of async callbacks in Runner.create function lodash/lodash#2768 and a prototype pollution vulnerability patched in lodash >=4.17.5 #133

ps1dr3x avatar Oct 25 '18 15:10 ps1dr3x

Thanks for your pull request. It looks like this may be your first contribution to a Google open source project (if not, look below for help). Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

:memo: Please visit https://cla.developers.google.com/ to sign.

Once you've signed (or fixed any issues), please reply here (e.g. I signed it!) and we'll verify it.


What to do if you already signed the CLA

Individual signers
Corporate signers

googlebot avatar Oct 25 '18 15:10 googlebot

I signed it!

ps1dr3x avatar Oct 25 '18 15:10 ps1dr3x

CLAs look good, thanks!

googlebot avatar Oct 25 '18 15:10 googlebot

@theganyo, @whitlockjc, This PR resolves a vulnerability reported by npm audit, https://www.npmjs.com/advisories/577

Please merge.

robert-claypool avatar Jan 30 '19 05:01 robert-claypool

Hi Folks,

Do you have any update about this Pull Request? I'm with problems of vulnerability in the lodash package, can you help me and merge this pull?

Vulnerability: https://www.npmjs.com/advisories/782

ccvictorviana avatar Jul 02 '19 16:07 ccvictorviana

Bump

robert-claypool avatar Jul 04 '19 23:07 robert-claypool

Any update on the merge? literally been a year since the pull request

sulaxchane avatar Dec 09 '19 09:12 sulaxchane

This project seems totally abandoned by the authors/maintainers

ps1dr3x avatar Dec 10 '19 09:12 ps1dr3x

Any update on releasing this PR? Looks like this project is no longer maintained. Should we switch to an alternate library?

sg002-reactive-prog avatar Dec 13 '19 15:12 sg002-reactive-prog