fkling / fkling/JSNetworkX

Lodash 3.10.1 in dependencies has a security issue

Open
#79 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
779
Forks
178
PR merge metrics
No merged PRs in 30d

Description

(https://nvd.nist.gov/vuln/detail/CVE-2018-3721)[https://nvd.nist.gov/vuln/detail/CVE-2018-3721]
Please update to version > 4.17.5

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by locating the dependency manifest and any lockfile that specify Lodash 3.10.1, then inspect how dependencies are installed and run the existing test suite. Done means Lodash is updated to a version newer than 4.17.5 and the project tests still pass.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.