jsdoctest icon indicating copy to clipboard operation
jsdoctest copied to clipboard

lodash dependency vulnerability - need for rebuild?

Open rogalmic opened this issue 5 years ago • 0 comments

  Low             Prototype Pollution                                           
                                                                                
  Package         lodash                                                        
                                                                                
  Patched in      >=4.17.5                                                      
                                                                                
  Dependency of   jsdoctest [dev]                                               
                                                                                
  Path            jsdoctest > dox > jsdoctypeparser > lodash                    
                                                                                
  More info       https://nodesecurity.io/advisories/577                        
                                                                                
                                                                                
  High            Prototype Pollution                                           
                                                                                
  Package         lodash                                                        
                                                                                
  Patched in      >=4.17.11                                                     
                                                                                
  Dependency of   jsdoctest [dev]                                               
                                                                                
  Path            jsdoctest > dox > jsdoctypeparser > lodash                    
                                                                                
  More info       https://nodesecurity.io/advisories/782                        
                                                                                
                                                                                
  High            Prototype Pollution                                           
                                                                                
  Package         lodash                                                        
                                                                                
  Patched in      >=4.17.12                                                     
                                                                                
  Dependency of   jsdoctest [dev]                                               
                                                                                
  Path            jsdoctest > dox > jsdoctypeparser > lodash                    
                                                                                
  More info       https://nodesecurity.io/advisories/1065                       
                                                                                
found 3 vulnerabilities (1 low, 2 high) in 1412 scanned packages
  3 vulnerabilities require manual review. See the full report for details.

rogalmic avatar Aug 16 '19 09:08 rogalmic