vizion icon indicating copy to clipboard operation
vizion copied to clipboard

Dependency on insecure Lodash version 4.17.19

Open jcass8695 opened this issue 3 years ago • 0 comments

Hey 👋

We are using PM2 in our project and we're getting security vulnerability warnings for Lodash versions prior to 4.17.21. Here are the CVEs: CVE-2021-23337 & CVE-2020-28500.

Looks like vizion is using an older version of async (2.6.3) which is throwing the warnings. async has had a major version bump since (releases), which should have squashed the vulnerability.

Could the maintainers update vizion, so in turn PM2 can also update. Thanks! 🙇

jcass8695 avatar Apr 08 '21 11:04 jcass8695