mrsum / webpack-svgstore-plugin

Simple svg-sprite creating with webpack
https://www.npmjs.com/package/webpack-svgstore-plugin
200 stars 92 forks source link

The transitive dependency lodash@4.17.2 has known vulnerabilities #192

Open yisehak-awm opened 2 years ago

yisehak-awm commented 2 years ago

Version 4.17.2 of lodash has these vulnerabilities

Update to v4.17.21 fixes all vulnerabilities.

mrsum commented 2 years ago

Hello @yisehak-awm, sorry for delay. Right now i working on new version of plugin with TS and other cool features, based on Webpack 5. Stay tune

yisehak-awm commented 2 years ago

Hi Mike, Great to hear from you. Will the new plugin be backward compatible with the old one? Our codebase is huge and is over a decade old. I put in pull requests for the version upgrades. We would love it if those changes went through. I would save us a lot of trouble. If the new plugin works with the old codebase that's great. Either way, we look forward to your upcoming works and thank you for your contribution on the plugin :) Hope to hear from you soon

On Wed, Mar 23, 2022 at 11:39 AM Mike Chernobrov @.***> wrote:

Hello @yisehak-awm https://github.com/yisehak-awm, sorry for delay. Right now i working on new version of plugin with TS and other cool features, based on Webpack 5. Stay tune

— Reply to this email directly, view it on GitHub https://github.com/mrsum/webpack-svgstore-plugin/issues/192#issuecomment-1076090221, or unsubscribe https://github.com/notifications/unsubscribe-auth/AFR7ZDUJALHBWRWRIC7QMRDVBLKD5ANCNFSM5RG7G3KA . You are receiving this because you were mentioned.Message ID: @.***>