Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Lodash Pick causes a security issue #219

Open
bcgilliom opened this issue Feb 9, 2024 · 1 comment
Open

Lodash Pick causes a security issue #219

bcgilliom opened this issue Feb 9, 2024 · 1 comment

Comments

@bcgilliom
Copy link

It seems the guidance is to no longer use the individual imports (they are basically deprecated) the security issue is fixed in the main package as of 4.17.19, but I think the individual packages (like pick) didn't get repacked on npm?

GHSA-p6mc-m468-83gw

lodash/lodash#5809

@shamas
Copy link

shamas commented Nov 25, 2024

Any updates on this? It's kind of annoying because the npm audit --fix installs a very outdated version of this package

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants