codymikol / karma-webpack

Karma webpack Middleware
MIT License
830 stars 222 forks source link

Security vulnerability in lodash version used by karma-webpack #425

Closed michdsouza closed 5 years ago

michdsouza commented 5 years ago

Expected Behavior

Upgrade to lodash version >=4.17.12

Actual Behavior

high Prototype Pollution
Package lodash
Patched in >=4.17.12
Dependency of karma-webpack
Path karma-webpack > lodash
More info https://www.npmjs.com/advisories/1065

Code

N/A

How Do We Reproduce?

Running a yarn audit

alexander-akait commented 5 years ago

Update webpack and webpack-karma to latest version