plone / plone.staticresources

Static resources for Plone
https://pypi.org/project/plone.staticresources/
5 stars 13 forks source link

Update underscore to address CVE-2021-23358 #160

Closed nutjob4life closed 2 years ago

nutjob4life commented 3 years ago

Unfortunately I have to ship Plone to government sites which use Twistlock Prisma Cloud to examine Docker images for vulnerabilities. It found one in underscore, included in plone.staticresources 1.4.1 through the present. The suggested remediation is to upgrade to underscore 1.12.1.

petschki commented 2 years ago

done in 5.x release