Update Vulnerable Dependency
Open
easy
good first issue
Hacktoberfest
help wanted
- Dominant language
- CoffeeScript
- Stars
- 7
- Forks
- 9
- PR merge metrics
- No merged PRs in 30d
Description
As per github the following dependencies need to be updated and are currently vulnerable:
- lodash
Contributor guide
No contributing guide indexed for this repository
Research direction
The issue identifies lodash as vulnerable but names no manifest, version, file, or test. Start by locating where dependencies are declared in this CoffeeScript project, then determine the safe lodash version from the reported GitHub advisory. Done means lodash is updated and the vulnerability is no longer reported, with the project’s available checks passing.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- coffeescript, javascript
- Domain
- security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100