alibaba / alibaba/funcraft

There is a vulnerability in lodash 4.17.15,upgrade recommended

Open
#1,074 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
931
Forks
128
PR merge metrics
No merged PRs in 30d

Description

https://github.com/alibaba/funcraft/blob/dc34bb754a887133bf321c7f72e20ed6cc41b112/package-lock.json#L4157-L4161

CVE-2020-8203

Recommended upgrade version:4.17.20

Contributor guide

No contributing guide indexed for this repository

Research direction

The affected dependency is identified in package-lock.json at lines 4157-4161; start by inspecting that lodash entry and its surrounding dependency metadata. Update the resolved version to 4.17.20 and verify that the lockfile no longer references 4.17.15, which is the stated completion condition for addressing CVE-2020-8203.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
security
Issue type
Bug
Difficulty
1/5
Estimated time
Under an hour
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.