apache / cordova-ios

Apache Cordova iOS
https://cordova.apache.org/
Apache License 2.0
2.15k stars 987 forks source link

Lodash Vulnerabilities #1109

Closed ravijangra closed 2 years ago

ravijangra commented 3 years ago

Bug Report

Lodash Version < 4.17.21 have security vulnerabities

https://snyk.io/vuln/npm:lodash@4.17.20

Problem

As per the following Lodash Version < 4.17.21 have vulnerabilities and these are fixed in 4.17.21 https://snyk.io/vuln/npm:lodash@4.17.20 https://github.com/lodash/lodash/issues/5083

What is expected to happen?

Can the lodash dependencies be updated soon.

What does actually happen?

Information

Command or Code

package.json/package-lock.json

Environment, Platform, Device

Version information

Checklist

ravijangra commented 2 years ago

Any update on this?