openbmc / phosphor-webui

Web-based user interface for managing OpenBMC systems
Apache License 2.0
37 stars 25 forks source link

Fix lodash security vulnerability #91

Closed gtmills closed 5 years ago

gtmills commented 5 years ago

See https://github.com/lodash/lodash/pull/4336 for more information. Need a npm update When I did a npm update on 7/23/19, not all packages were using the fixed version of lodash. (E.g. babel-core is still using 4.17.11 https://github.com/babel/babel/issues/10226 )

https://gerrit.openbmc-project.xyz/c/openbmc/phosphor-webui/+/23782 only partially addresses.