Skip to content

vue-test-utils using vulnerable version of lodash #1275

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
Sumeshkumar opened this issue Jul 17, 2019 · 1 comment
Closed

vue-test-utils using vulnerable version of lodash #1275

Sumeshkumar opened this issue Jul 17, 2019 · 1 comment

Comments

@Sumeshkumar
Copy link

Version

1.0.0-beta.29

Reproduction link

https://github.com/vuejs/vue-test-utils

Steps to reproduce

https://snyk.io/vuln/SNYK-JS-LODASH-73638

What is expected?

Update to stable version >= 4.17.13

What is actually happening?

Vulnerable package is using

lmillucci added a commit to lmillucci/vue-test-utils that referenced this issue Aug 27, 2019
bump karma version to ^3.1.4
update lerna URL on docs
@brandonburkett
Copy link

Has this update actually be published? 1.0.0-beta.29 still has the older version of lodash.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants