icodeforlove / node-cloudflare

Node.js CloudFlare V4 API wrapper
MIT License
30 stars 14 forks source link

Update dependency lodash #18

Closed sfxworks closed 5 years ago

sfxworks commented 5 years ago
                       === npm audit security report ===

                                 Manual Review
             Some vulnerabilities require your attention to resolve

          Visit https://go.npm.me/audit-guide for additional guidance

  Low             Prototype Pollution

  Package         lodash

  Patched in      >=4.17.5

  Dependency of   cloudflare4

  Path            cloudflare4 > lodash

  More info       https://nodesecurity.io/advisories/577

https://hackerone.com/reports/310443 Lodash should be updated to at least 4.17.5 for this package due to this report.