metakgp / metakgp/eva

Update Vulnerable Dependency

Open
#22 0 comments 0 reactions 0 assignees View on GitHub
easy good first issue Hacktoberfest help wanted
Dominant language
CoffeeScript
Stars
7
Forks
9
PR merge metrics
No merged PRs in 30d

Description

As per github the following dependencies need to be updated and are currently vulnerable:

- lodash

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue identifies lodash as vulnerable but names no manifest, version, file, or test. Start by locating where dependencies are declared in this CoffeeScript project, then determine the safe lodash version from the reported GitHub advisory. Done means lodash is updated and the vulnerability is no longer reported, with the project’s available checks passing.

Written by the indexing model from the issue text.

Assessment

Tech stack
coffeescript, javascript
Domain
security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.