-
Notifications
You must be signed in to change notification settings - Fork 2.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Medium severity vulnerability found in lodash #1620
Comments
Bump |
We don't use that method so it doesn't apply to us. We removed lodash in
v3.0. I think there were some issues for us to migrate off that minor
version of lodash on the 2.x line of Async.
…On Fri, Feb 8, 2019, 2:12 AM Daniel Scalzi ***@***.*** wrote:
Bump
—
You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub
<#1620 (comment)>, or mute
the thread
<https://github.com/notifications/unsubscribe-auth/AAiEbmULsTIq6AwY5RHZJNcM60O1Lw7tks5vLWmygaJpZM4ah0sH>
.
|
aearly
added a commit
that referenced
this issue
Feb 12, 2019
Updating lodash was no issue, I've published v2.6.2 with the update. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
snyk
reports a Regular Expression Denial of Service vulnerability on one of your dependencies, lodash4.17.5
.and
Thanks in advance!
The text was updated successfully, but these errors were encountered: