salesforce / salesforce/design-system-react

Security Vulnerability: lodash.isDate Dependency in @salesforce/design-system-react

Open
#3,182 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
JavaScript
Stars
982
Forks
440
Avg merge
1d 21h
Merged PRs (30d)
4

Description

Hi team,

We've identified a security vulnerability associated with the lodash.isDate package, which is still being used as a dependency in the latest version of @salesforce/design-system-react.

https://www.npmjs.com/package/lodash.isdate

The lodash.isDate package has not received any updates in over 9 years.
A security issue has been flagged in this library, raising concerns about its continued usage.
The latest release of @salesforce/design-system-react still includes this dependency.

Could you please confirm:

Whether any APIs or functions from lodash.isDate are actively used within the package?
If there are any plans to remove or replace this dependency with a more secure and actively maintained alternative?

Thanks for looking into this! Looking forward to hearing back from you.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No source files or tests are named. Start by locating the dependency declaration for lodash.isDate and searching the package for its usage; determine whether it is still required and document a confirmed removal or replacement path.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript, react
Domain
frontend, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.