dresende / node-orm2

Object Relational Mapping
http://github.com/dresende/node-orm2
MIT License
3.07k stars 379 forks source link

Update for CVE-2018-16487 around lodash #845

Closed aeppert closed 4 years ago

bluet commented 4 years ago

@aeppert seems there are still some inconsistencies. Can you check the travis-ci output error msgs and try to fix it?

P.S. I'm not a maintainer of this projects, just offering my feedback and hope @dresende can take a look when all the tests are pass.

dxg commented 4 years ago

Thanks for raising this. Wasn't practical to fix in here, however I've resolved it in the PR linked above. New version with the fix has been published - v5.0.5