There is a vulnerability in set-value 0.4.3,upgrade recommended
Open
- Dominant language
- JavaScript
- Stars
- 193
- Forks
- 112
- PR merge metrics
- No merged PRs in 30d
Description
https://github.com/Autodesk/hig/blob/80680833679c324da5bb36cfe74f36c15c9672bc/acceptance/yarn.lock#L9499-L9502
CVE-2019-10747
Recommended upgrade version:2.0.1
Contributor guide
Research direction
Inspect acceptance/yarn.lock at lines 9499-9502 and confirm how set-value 0.4.3 is resolved. Update the dependency resolution to the recommended 2.0.1 version, then verify that the lockfile no longer includes the vulnerable version.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- security
- Issue type
- Bug
- Difficulty
- 1/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 45/100