bob983 / hexo-multiauthor

11 stars 7 forks source link

A dependency is vulnerable #7

Open noraj opened 5 years ago

noraj commented 5 years ago
$  npm audit

                       === npm audit security report ===

│                                Manual Review                                 │
│            Some vulnerabilities require your attention to resolve            │
│                                                                              │
│         Visit for additional guidance          │
│ Low           │ Prototype Pollution                                          │
│ Package       │ lodash                                                       │
│ Patched in    │ >=4.17.5                                                     │
│ Dependency of │ hexo-multiauthor                                             │
│ Path          │ hexo-multiauthor > lodash                                    │
│ More info     │                       │
│ Low           │ Prototype Pollution                                          │
│ Package       │ lodash                                                       │
│ Patched in    │ >=4.17.5                                                     │
│ Dependency of │ hexo-multiauthor                                             │
│ Path          │ hexo-multiauthor > warehouse > lodash                        │
│ More info     │                       │
│ Low           │ Regular Expression Denial of Service                         │
│ Package       │ uglify-js                                                    │
│ Patched in    │ >=2.6.0                                                      │
│ Dependency of │ hexo-deployer-git                                            │
│ Path          │ hexo-deployer-git > swig > uglify-js                         │
│ More info     │                        │
found 3 low severity vulnerabilities in 3801 scanned packages
  3 vulnerabilities require manual review. See the full report for details.