Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

lodash minor vulnerability #81

Open
mcnahum opened this issue Feb 12, 2019 · 0 comments
Open

lodash minor vulnerability #81

mcnahum opened this issue Feb 12, 2019 · 0 comments

Comments

@mcnahum
Copy link

mcnahum commented Feb 12, 2019

I guess the package need a small update ...

found 1 low severity vulnerability
run npm audit fix to fix them, or npm audit for details
root@oznu-homebridgeV2_DEB:/homebridge# npm audit

                   === npm audit security report ===                                                                         
                                                                                                                             
                                                                                                                             
                             Manual Review                                                                                   
         Some vulnerabilities require your attention to resolve                                                              
                                                                                                                             
      Visit https://go.npm.me/audit-guide for additional guidance                                                            

Low Prototype Pollution

Package lodash

Patched in >=4.17.5

Dependency of homebridge-netatmo

Path homebridge-netatmo > node-cache > lodash

More info https://nodesecurity.io/advisories/577

found 1 low severity vulnerability in 12943 scanned packages
1 vulnerability requires manual review. See the full report for details.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant