Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Multiple vulnerabilities through lodash dependency #15

Open
sgspinola opened this issue Nov 26, 2020 · 0 comments
Open

Multiple vulnerabilities through lodash dependency #15

sgspinola opened this issue Nov 26, 2020 · 0 comments

Comments

@sgspinola
Copy link

Describe the bug
The horsey dependency declared at package.json brings a lodash version that has multiple known vulnerabilities.

Additional context
As you can see at Snyk's Vuln DB only the latest version has no known direct vulnerabilities. Since no new version from horsey has been published, and the lodash dependency at horsey is declared using a specific version, I suggest the use of another library for this functionality or the removal of the dependency.

Another option would be to open an issue to the horsey repo, but it has had no activity since 2016.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant