Security: update NPMs in website/package-lock.json due to security issues
- Dominant language
- Java
- Stars
- 14.1k
- Forks
- 3.8k
- Avg merge
- 2d 58m
- Merged PRs (30d)
- 233
Description
### Description
There are a large number of NPMs with security issues in use - lodash, postcss, inmer, url-parse are ones that pop up a lot in dependabot anayses.
### Motivation
Please provide the following for the desired feature or change:
- A detailed description of the intended use case, if applicable
- Rationale for why the desired feature/change would be beneficial
Contributor guide
Research direction
Start by inspecting website/package-lock.json and the lodash, postcss, inmer, and url-parse entries mentioned in the issue, then review the related Dependabot security findings. Done means the reported vulnerable NPM dependencies are updated in the lockfile and the resulting dependency state is checked.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- build-system, frontend, security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100