lodash:4.17.15组件存在CVE-2020-8203漏洞建议升级
Open
area/dashboard
good first issue
- Dominant language
- Java
- Stars
- 23.1k
- Forks
- 8.1k
- PR merge metrics
- No merged PRs in 30d
Description
https://github.com/alibaba/Sentinel/blob/55a8294ab0afb08c6c048e541cf8a99c49069dac/sentinel-dashboard/src/main/webapp/resources/package-lock.json#L2418-L2421
推荐升级版本:
4.17.20
Contributor guide
Research direction
Start with sentinel-dashboard/src/main/webapp/resources/package-lock.json at lines 2418-2421 and inspect the lodash dependency entry. Update the recorded version to 4.17.20, then verify that the dashboard dependency metadata remains consistent and the vulnerability is no longer reported.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- security
- Issue type
- Bug
- Difficulty
- 1/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 45/100