Lodash 3.10.1 in dependencies has a security issue
Open
- Dominant language
- JavaScript
- Stars
- 779
- Forks
- 178
- PR merge metrics
- No merged PRs in 30d
Description
(https://nvd.nist.gov/vuln/detail/CVE-2018-3721)[https://nvd.nist.gov/vuln/detail/CVE-2018-3721]
Please update to version > 4.17.5
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by locating the dependency manifest and any lockfile that specify Lodash 3.10.1, then inspect how dependencies are installed and run the existing test suite. Done means Lodash is updated to a version newer than 4.17.5 and the project tests still pass.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 35/100