cloud-native-toolkit / cloud-native-toolkit/planning

node react starter template has security CVE that makes trivy task to fail

Open
#586 0 comments 0 reactions 0 assignees View on GitHub
bug
Dominant language
No language data
Stars
4
Forks
1
PR merge metrics
No merged PRs in 30d

Description

```
opt/app-root/src/client/package-lock.json
=========================================
Total: 1 (CRITICAL: 1)

+-----------------+------------------+----------+-------------------+---------------+--------------------------------+
| LIBRARY | VULNERABILITY ID | SEVERITY | INSTALLED VERSION | FIXED VERSION | TITLE |
+-----------------+------------------+----------+-------------------+---------------+--------------------------------+
| lodash.template | CVE-2019-10744 | CRITICAL | 4.4.0 | 4.5.0 | nodejs-lodash: prototype |
| | | | | | pollution in defaultsDeep |
| | | | | | function leading to modifying |
| | | | | | properties |
+-----------------+------------------+----------+-------------------+---------------+--------------------------------+

```

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.