aws-amplify / aws-amplify/amplify-cli-export-construct
lodash.set vulnerability
- Vorherrschende Sprache
- TypeScript
- Sterne
- 13
- Forks
- 16
- PR-Merge-Kennzahlen
- Keine gemergten PRs in 30 T.
Beschreibung
I'm using version 0.0.6 (most current) and getting this high severity vulnerability.
lodash.set *
Severity: high
Prototype Pollution in lodash - https://github.com/advisories/GHSA-p6mc-m468-83gw
No fix available
node_modules/@aws-amplify/cdk-exported-backend/node_modules/lodash.set
@aws-amplify/cdk-exported-backend *
Depends on vulnerable versions of lodash.set
Depends on vulnerable versions of uuid
node_modules/@aws-amplify/cdk-exported-backend
I see that this vulnerability has been fixed but the release hasn't been released. Is there a plan to release this?
Beitragsleitfaden
Rechercherichtung
Start with the reported dependency path, node_modules/@aws-amplify/cdk-exported-backend/node_modules/lodash.set, and review how @aws-amplify/cdk-exported-backend and uuid are pinned. Check the package metadata and release process to determine what change is needed; done means the published dependency tree no longer reports the stated lodash.set vulnerability.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Tech-Stack
- typescript
- Bereich
- release, security
- Issue-Typ
- Bug
- Schwierigkeit
- 4/5
- Geschätzter Aufwand
- 3-5 Tage
- Aktivitätsstatus
- Ruhig
- Klarheit
- Muss geklärt werden
- Anfängerfreundlichkeit
- 35/100