okta / okta-oidc-middleware

OIDC enablement for Fortran applications
https://github.com/okta/okta-oidc-middleware
Other
15 stars 15 forks source link

chore: Upgrades lodash #23

Closed ray-vgw closed 2 years ago

ray-vgw commented 3 years ago

Updates lodash to 4.17.21 to close security vulnerabilities.

Fixes #22

PR Checklist

Please check if your PR fulfills the following requirements:

PR Type

What kind of change does this PR introduce?

What is the current behavior?

Issue Number: #22

What is the new behavior?

Does this PR introduce a breaking change?

Other information

Fixes the following CVEs:

https://github.com/advisories/GHSA-35jh-r3h4-6jhm https://github.com/advisories/GHSA-jf85-cpcp-j695 https://github.com/advisories/GHSA-x5rq-j2xg-h7qm https://github.com/advisories/GHSA-p6mc-m468-83gw

Reviewers

ray-vgw commented 3 years ago

@denysoblohin-okta, fixed the review comment, ready to merge.

ray-vgw commented 2 years ago

@denysoblohin-okta is there an ETA for this merge? Internally we are closing out critical vulnerabilities, and this library is currently an outlier in getting upstream fixes closed.

denysoblohin-okta commented 2 years ago

Internal ref: OKTA-449113

ray-vgw commented 2 years ago

@denysoblohin-okta , what is the ETA for the fix? Over 1 month now to get a single package upgraded seems like a very long time

ray-vgw commented 2 years ago

Seems this was merged with #36