metafizzy / metafizzy/packery

(requirejs)Security Vulnerability: Prototype polution

Open
#566 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
4.3k
Forks
324
PR merge metrics
No merged PRs in 30d

Description

Are there any chances of getting requirejs update in gulp-requirejs-optimize?
requirejs recently fixed the Security Vulnerability: Prototype pollution.
[https://github.com/requirejs/requirejs/commit/ebd7a2ff71473542fa132d0d15c10fb4ed1539e1](https://github.com/requirejs/requirejs/commit/ebd7a2ff71473542fa132d0d15c10fb4ed1539e1)
[https://security.snyk.io/vuln/SNYK-JS-REQUIREJS-5416713](https://security.snyk.io/vuln/SNYK-JS-REQUIREJS-5416713)

Contributor guide

Open the contributing guide

Research direction

Start by locating the dependency declaration for gulp-requirejs-optimize in the repository and compare its requirejs version with the linked requirejs security fix and Snyk advisory. Done means the dependency uses a version containing the prototype-pollution fix and the project’s dependency or security checks pass.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
build-system, security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.