vizion
vizion copied to clipboard
Dependency on insecure Lodash version 4.17.19
Hey 👋
We are using PM2 in our project and we're getting security vulnerability warnings for Lodash versions prior to 4.17.21. Here are the CVEs: CVE-2021-23337 & CVE-2020-28500.
Looks like vizion is using an older version of async (2.6.3) which is throwing the warnings. async has had a major version bump since (releases), which should have squashed the vulnerability.
Could the maintainers update vizion, so in turn PM2 can also update. Thanks! 🙇