naz / swagger-express-validator

Lightweight requrest/response validation middleware based on swagger/OpenAPI schema
MIT License
56 stars 24 forks source link

Lodash dependency has security issue #46

Closed davesag closed 5 years ago

davesag commented 5 years ago

See https://github.com/lodash/lodash/pull/4336

Fix is to update Lodash to 4.17.14 or (better) to remove the dependency on Lodash completely as there's pretty much nothing it's being used for that can't be done with vanilla ES6 javascript.

naz commented 5 years ago

Thanks for heads up @davesag!