cube
cube copied to clipboard
CVE-2019-10744 in dependency
Hello,
your package hive-driver is using jshs2 which is very old and uses version of lodash targeted in critical CVE-2019-10744
thank you for your product :) regards
Hello @a-legrand ,
Thank you for submitting the issue. It's true, I did the PR - https://github.com/imjuni/jshs2/pull/23
It's still not merged )))))
Thanks
oh wow!
thank you for your reply :)