(requirejs)Security Vulnerability: Prototype polution
- Dominant language
- JavaScript
- Stars
- 4.3k
- Forks
- 324
- PR merge metrics
- No merged PRs in 30d
Description
Are there any chances of getting requirejs update in gulp-requirejs-optimize?
requirejs recently fixed the Security Vulnerability: Prototype pollution.
[https://github.com/requirejs/requirejs/commit/ebd7a2ff71473542fa132d0d15c10fb4ed1539e1](https://github.com/requirejs/requirejs/commit/ebd7a2ff71473542fa132d0d15c10fb4ed1539e1)
[https://security.snyk.io/vuln/SNYK-JS-REQUIREJS-5416713](https://security.snyk.io/vuln/SNYK-JS-REQUIREJS-5416713)
Contributor guide
Research direction
Start by locating the dependency declaration for gulp-requirejs-optimize in the repository and compare its requirejs version with the linked requirejs security fix and Snyk advisory. Done means the dependency uses a version containing the prototype-pollution fix and the project’s dependency or security checks pass.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- build-system, security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100